DNSã«åå ¥é: DNSãµãŒããŒ(ãã«ãªãŸã«ã)ãå®éã®å®¶åºãå®äŸã亀ããŠè©³è§£ãã
â»ãã®èšäºã¯èªåãæå±ããçµç¹ã§æžãã以äžã®èšäºã®ã³ããŒã§ããæçš¿ããèšäºã¯å人ã®èäœç©ãšããŠèªããã°ã«ã³ããŒããŠè¯ãã«ãŒã«ãšããŠããŸãã
å èšäº: https://tech-blog.mitsucari.com/entry/2025/11/10/100411
ããã«ã¡ã¯ãããã«ãªCTOã®å¡æ¬ããšãã€ãã³ãŒ(@tsukaby0) ã§ãã
ååã®èšäºã§ã¯åŒç€Ÿã®ã€ã³ã¿ãŒã³ã®äºäžãããDNSã®æŽå²ã«ã€ããŠè§£èª¬ããŠãããŸããã
ä»åã¯DNSãµãŒããŒã«ãã©ãŒã«ã¹ãåœãŠãŠèª¬æãããŠã¿ãããšæããŸããDNSãµãŒããŒãšäžèšã§èšã£ãŠããã«ãªãŸã«ããæš©åšãµãŒããŒããã£ããããã以å€ã«ãããã€ãçš®é¡ããã£ããããŸããæžç±çã§é¢ä¿æ§ãåãåãããå³ç€ºãããŠãããããŸãããå ·äœçã«ã€ã¡ãŒãžããã®ã¯å°ãé£ããã§ãããã®ãããã詳ãã説æããŠã¿ãŸãã
æŠèŠ
- 倧æµã®å®¶åºã§ã¯ãã«ãªãŸã«ãã¯ISPã®DNSãµãŒããŒãšããçè§£ã§è¯ããã詳现ã¯èª¿ã¹ããããªã
- ãã«ãªãŸã«ãã®åã«ãã©ã¯ãŒããŒãããã±ãŒã¹ããã
- ãšã³ã¿ãŒãã©ã€ãºã§ã¯èªç€Ÿã§DNSãµãŒããŒãæã€ããšããã
DNSã®åºç€ç¥è
DNSã®åºç€ã¯ç§ãæžããããå 人ãå€ãèšäºãæ®ããŠããããããã¡ããã芧ãã ããã

æžç±ã ãšã DNSããããããæç§æž ãè©å€ã®ããã§ããããã®ç¬¬äºçãåºããããªã®ã§ããã¡ããè²·ã£ãŠã¿ãã®ãè¯ããšæããŸãã
ããããå³ãšçå
ã€ã³ã¿ãŒãããäžã®æ§ã ãªèšäºã§DNSãå³è§£ãããŠããŸããäŸãã°ä»¥äžã¯JPNICã®äŸã§ãã

åŒçšå : ã€ã³ã¿ãŒããã10åè¬åº§ DNS - JPNIC https://www.nic.ad.jp/ja/newsletter/No22/080.html
ãã®å³ãèŠããšç¢ºãã«æŠèŠã¯çè§£ã§ããŸããããåãåãããè¡ãããã®ãµãŒããŒããšã¯äœã ïŒãšããçåãæ¹§ããŸãããã¡ããããã¯æŠèŠãªã®ã§ããã®å³ã¯ããã§è¯ãã®ã§ãããå°ãèžã¿èŸŒãã å³ã§ã¯ãã«ãªãŸã«ããšãã説æãåºãŠããŸããããããŸãçåãæ¹§ããŸãããã«ãªãŸã«ãã®å®æ ãšã¯äœãªã®ã§ããããïŒ
ãã®èŸºããèžã¿èŸŒãã§è§£èª¬ããŠããè³æãèŠã€ãããªãã£ãã®ã§ãèªåã§èª¿æ»ã解説ããããšæããŸãã
ãã«ãªãŸã«ãã¯ISPã®DNSãµãŒããŒ
ãã«ãªãŸã«ããšã¯å€§æµã®å®¶åºã«ãããŠã¯ISPãæäŸããŠããDNSãµãŒããŒãæããŸãããã ãã詳现ã«ã€ããŠã¯ãããã€ãåŽã®ç€Ÿå€ç§æ å ±ã«è©²åœãããšäºæ³ããããããWebäžã«ã¯æ å ±ããããŸããã
ããã ãã ãšã€ãŸããªãã®ã§ãããå°ã詳现ã«è§£èª¬ããŸãã
ã«ãŒã¿ãŒãšãããã€ãã®èªèšŒãIPãšDNSé åž
ãŸããäžè¬å®¶åºã§ã¯ãäœããã®ãããã€ããšå¥çŽããŠã€ã³ã¿ãŒãããåç·ãå©çšã§ããããã«ãããšæããŸãããããã€ãããèªèšŒæ å ±ãåãåããã«ãŒã¿ãŒã«èšå®ããŸãããã®æã«ãŒã¿ãŒå éšã§ã¯èªèšŒæ å ±ã䜿ã£ãŠèªèšŒãããããã€ãããæ¥ç¶æ å ±ãåãåããŸãããã®æ¥ç¶æ å ±ã«ã¯ã°ããŒãã«IPã¢ãã¬ã¹ãDNSãµãŒããŒã®ã¢ãã¬ã¹ãå«ãŸããŸãã以äžã¯å®éã«ç§ã®ã«ãŒã¿ãŒã«èšå®ãããŠããäŸã§ãã

(â»ã¡ãªã¿ã«ç§ã®å Žåã¯So-net + ãã¬ããå ã§v6ãã©ã¹ã®ãµãŒãã¹ãå©çšããŠããŸã)
èªèšŒæã®ãããã³ã«ã¯PPPoEã ã£ããIPv4 over IPv6 (MAP-EãŸãã¯DS-Lite)ã ã£ããããã®ã§ãããDNSããéžããã®ã§å²æããŸãã詳现ã¯åçš®ãããã€ãã解説ããŠããããããã¡ããã芧ãã ããã
èªèšŒãçµãã£ãåŸã¯ã«ãŒã¿ãŒã«ã°ããŒãã«IPãDNSã®ã¢ãã¬ã¹ãé ãããŸããããã¯PPPoEã®å ŽåãIPCPã§ãIPv4 over IPv6ã®å ŽåãSLAACãDHCPv6ãšããä»çµã¿ã§é ãããŸãããã®èŸºãã詳现ã¯å²æããŸãã以äžã®èšäºãªã©ãã芧ãã ããã
ãšã«ãããã®ãããªä»çµã¿ã§DNSãã«ãŒã¿ãŒã«èšå®ãããŸããããã«ãã£ãŠèªåã®PCããè¡ãããDNSã¯ãšãªãæåããããã«ãªããŸãã
ã«ãŒã¿ãŒãšPCéã®éä¿¡
å çšè»œãè§ŠããŸããããæšä»ã§ã¯ãããã€ãããå®¶åºã®ã«ãŒã¿ãŒãŸã§IPãé ãããæã«å¿ ãããDHCPã䜿ããããšã¯éããŸãããããããã«ãŒã¿ãŒããPCãžIPãé ãããå Žåã¯DHCPãäž»æµã ãšæãããŸãããšã«ããPCããWifiãLANã±ãŒãã«çãçµç±ããŠã«ãŒã¿ãŒãŸã§æ¥ç¶ãããšDHCPãªã©ã«ãã£ãŠèªåã§IPãªã©ãé ãããŸããé ãããæ å ±ã¯å®éã«ç¢ºèªããããšãã§ããŸãã
> scutil --dns
DNS configuration
resolver #1
search domain[0] : flets-east.jp
search domain[1] : iptvf.jp
nameserver[0] : 240b:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx
nameserver[1] : 192.168.10.1
if_index : 11 (en0)
flags : Request A records, Request AAAA records
reach : 0x00020002 (Reachable,Directly Reachable Address)
(åŸç¥)
nameserverãšããéšåã«IPv6ãšIPv4ã®ã¢ãã¬ã¹ãèšå®ãããŠããŸãããããã¯ã«ãŒã¿ãŒã®ã¢ãã¬ã¹ã§ããã€ãŸãDNSåãåããã¯ãŸããããã®ãµãŒããŒ(ã«ãŒã¿ãŒ)ã«å¯ŸããŠè¡ãããŸãã
ã«ãŒã¿ãŒã¯DNSãã©ã¯ãŒããŒã®å¯èœæ§ãé«ã
ãããŸã§ã®è©±ãç°¡åã«ãŸãšãããšãPCã®nameserver(DNS)ã¯ã«ãŒã¿ãŒãã«ãŒã¿ãŒã«èšå®ãããŠããDNSã¯ãããã€ãããæäŸãããã¢ãã¬ã¹ããšããããšã«ãªããŸãã
äœãèšãããããšãããšãããããå³ã§ã¯ãã«ãªãŸã«ãã¯ïŒã€ã ã衚瀺ãããŠããŸãããããã¯ååæ£è§£ã§ãã宿 ã¯ç°ãªããšããããšã§ãã

åŒçšå : JPRSçšèªèŸå žïœååž°çåãåããïŒrecursive queryïŒ https://jprs.jp/glossary/index.php?ID=0173
å®éã«ã¯PC(DNSã¯ã©ã€ã¢ã³ã)ãšãã«ãªãŸã«ãã®éã«å¥çš®ã®DNSãµãŒããŒãæãŸã£ãŠããããšããããŸãããããã¯
- DNSãã£ãã·ã¥ãµãŒããŒ
- DNSãã©ã¯ãŒããŒ
ãªã©ãšèšãããããšããããŸãããã£ãã·ã¥ãµãŒããŒã¯ãã«ãªãŸã«ããæ ã£ãŠããããšããããŸãããããããã¯ãã®ã±ãŒã¹ãå€ãã§ãããããã©ã¯ãŒããŒã¯åã«DNSã¯ãšãªã転éããã ãã®ãã®ã§ãã(ãŸããæãŸã£ãŠããDNSãµãŒããŒã¯ïŒã€ãšã¯éããŸããã)
ç§ã¯AtermãšããNEC補ã®ã«ãŒã¿ãŒãå©çšããŠããŸãããã©ãããããã«åãã£ãŠããDNSæ©èœã¯ãã«ãªãŸã«ãããã£ãã·ã¥ãµãŒããŒã§ã¯ãªãããã©ã¯ãŒããŒã®ããã§ãã
DNSãã©ã¯ãŒãã£ã³ã°æ©èœãšã¯ãæ¬ååã«æ¥ç¶ãããŠããåããœã³ã³ãªã©ããDNSã®åãåãããã±ãããåãåããšãã€ã³ã¿ãŒãããäžã®DNSãµãŒãã«ãã©ã¯ãŒãã£ã³ã°ããŠåãåãããåãåãããIPã¢ãã¬ã¹ãåããœã³ã³ã«åçããæ©èœã§ããæ¬ååã«æ¥ç¶ãããããœã³ã³ãªã©ããã¯ãæ¬ååãDNSãµãŒããšããŠåäœããŠããããã«èŠããŸãã
åŒçšå : https://www.aterm.jp/function/wg2600hs2/guide/dns_proxy.html
人ã«ãã£ãŠç°å¢ã¯ç°ãªããŸãããç§ã®å Žåã¯ã«ãŒã¿ãŒã¯åãªããã©ã¯ãŒããŒã§ãã«ãªãŸã«ãã¯ISPãæäŸããŠãããã®ããšèšãããã§ãã
ãããã€ãã§ã¯ãªãå åç·ãµãŒãã¹äºæ¥è ãDNSãµãŒããŒãæäŸãã
å çšãå°ãæžããŸããããç§ã¯So-netãšãããããã€ããšNTTæ±æ¥æ¬ã®ãã¬ããå ãå©çšããŠããŸããåºæ¬çã«NTTåŽã¯åç·ã®æäŸã§ãµãŒãã¹ã®æäŸã¯ãããã€ãããšããèªèã§ããããã®ãããSo-netã®DNSãå©çšããŠããã®ã ãšæã£ãŠããŸããããã©ããããã¬ããããããã¯IPv6ç°å¢ã«ãããŠã¯å°ãäºè±¡ãç°ãªãããã§ãã
å
çšã®ã¹ã¯ãªãŒã³ã·ã§ããã®éãã«ãŒã¿ãŒã«èšå®ãããDNS㯠2404:1a8:7f01:a::3 ã§ããããã®ã¢ãã¬ã¹ã§ãããæ€çŽ¢ãããšNTTæ±æ¥æ¬ã®DNSãšããæ
å ±ãåºãŠããŸãããã ããå
Œξ
å ±ãªã®ãã©ããå°ãæªãããšããã¯ãããŸãã
ãã«ãªãŸã«ãã¯å€ãããã
倧æµã®å Žåã¯ãã«ãŒã¿ãŒã«ãã£ãŠèªåã§PCãå©çšããDNSãèšå®ãããŸããããããã€ããDNS(ãã«ãªãŸã«ã)ãæäŸããŠããããããæã ãããåç·ãŠãŒã¶ãŒã¯ç¹ã«DNSãæèããå¿ èŠã¯ãããŸãããããããããããšæãã°æå³çã«å©çšããDNSã倿Žã§ããŸãã
ããããæåãªæ¹æ³ãšããŠã¯ãGoogleã®Public DNSãå©çšããæ¹æ³ã§ãã

ããã«ã€ããŠã¯è§£èª¬ããŠããèšäºã¯å€ãã®ã§è©³çްã¯å²æããŸããèªèº«ã®PCã®DNSèšå®ã 8.8.8.8 ãªã©ã«å€ããã ãã§ãã
ä»ã«ãèªåã§DNSãµãŒããŒã建ãŠããšããæ¹æ³ããããŸããäŸãã°DNSã§æåãªBindãšãããœãããŠã§ã¢ããããŸãããããã䜿ã£ãŠèªåã§DNSãµãŒããŒã建ãŠãããšãã§ããŸãã
詳现ãªããæ¹ã«ã€ããŠã¯å²æããŸãã以äžã®èšäºãªã©ãåèã«ãªããŸãã

ãã«ãªãŸã«ããšDNSãã£ãã·ã¥ãµãŒããŒã¯ã»ãŒåãæå³
ããããDNSã«ã€ããŠåŠç¿ããŠãããšãã«ãªãŸã«ããšèšã£ããDNSãã£ãã·ã¥ãµãŒããŒãšèšã£ããããè³æãåºãŠããŸããããããïŒã€ã¯ã»ãŒåãæå³ãšæããŠãè¯ããããããŸããããã ããéãã«ã€ããŠã¯çè§£ããŠãããšè¯ããããããŸããã
äŸãã°å ã»ã©BindãäŸã«åºããŸããããBindã¯èšå®ãã¡ã€ã«ã«å¿ããŠ
- æš©åšãµãŒããŒãšããŠæ¯ãèãã®ã
- ãã«ãªãŸã«ã(èªåã§åå解決ãã)ãšããŠæ¯ãèãã®ã
- DNSãã£ãã·ã¥ãµãŒããŒ(èªåã§è§£æ±ºããã«ãã©ã¯ãŒã)ãšããŠæ¯ãèãã®ã
- DNSãã©ã¯ãŒããŒ(ãã£ãã·ã¥ãããªã)ãšããŠæ¯ãèãã®ã
ãåãæ¿ããããšãã§ããŸãã
ãã詳现ã«ã¯ã以äžã®ãããªèšå®ãªãã·ã§ã³ãååšããŸãã®ã§ãããããçµã¿åãããããšã§å®çŸããŸãã
recursionã¯ååž°çåãåããããããã©ãããªã®ã§ãããã«ãã£ãŠæš©åšãµãŒããŒããã®ä»ããæ±ºãŸããŸãã
forwardã¯ãã©ã¯ãŒããããã©ãããforwardersã¯å®éã«ãã©ã¯ãŒãããå ã§ãã
max-cache-ttlãšããèšå®ããããããã«ãã£ãŠãã£ãã·ã¥ãå®è³ªããªãèšå®ãå¯èœãªããã§ããmax-cache-sizeãšããèšå®ãããããã§ããã0ã«èšå®ãããšç¡å¶éã«ãã£ãã·ã¥ãããšããèšå®ã«ãªããããªã®ã§ããã¡ãã¯äœ¿ããªãããã§ãã
recursionãæå¹ã«ãªã£ãŠããããã«ãªãŸã«ããšããŠåãããèªåã解決ã§ããªãã¯ãšãªã¯ä»ã®DNSã«ãã©ã¯ãŒããããšããèšå®ãã§ããã®ã§ããã«ãªãŸã«ãã ããã£ãã·ã¥ãµãŒããŒã ãããã©ã¯ãŒããŒã§ãããããšããã±ãŒã¹ãããããã§ãã
ãšã³ã¿ãŒãã©ã€ãºã®å Žåã瀟å ã§DNSãµãŒããŒãæã€
ãããŸã§ã¯äžè¬çãªå®¶åºãå°èŠæš¡ã®ãªãã£ã¹ãæ³å®ãã話ãããŸããããå€§äŒæ¥ã§ã¯è©±ã¯å°ãå€ãã£ãŠããŸãã
çç±ã¯åçŽã§æ§ã ãªã»ãã¥ãªãã£çã®èŠä»¶ããèªåã§DNSãµãŒããŒãæã€ããšãå€ãããã§ããã€ãŸãISPããæäŸãããDNSãå©çšããªãã±ãŒã¹ãããããŸãã
補åãšããŠã¯äŸãã°InfobloxããããŸããå ¬åŒãµã€ãããã¯ä»¥äžã®å ¬åŒnoteèšäºã®æ¹ãåããããããããããŸããã

ãšã³ã¿ãŒãã©ã€ãºã®å Žåãæ§ã ãªã»ãã¥ãªãã£ãªã¹ã¯ãã³ã³ãã©ã€ã¢ã³ã¹èŠä»¶ãæºããããã«çްãããããã¯ãŒã¯ãèšèšããå¿ èŠããããŸããäžèšnoteã®åŒçšã§ããã以äžã®ãããªãã¹ããã©ã¯ãã£ã¹ã®ã·ã¹ãã ã¢ãŒããã¯ãã£å³ã¯åèã«ãªããé¢çœãã§ãããæ°ã«ãªãæ¹ã¯ãã²èšäºå ã®è§£èª¬ãã芧ãã ããã

åŒçšå : Infobloxãèããããã¹ãDNSãµãŒããŒã®æ§æå³ - InfobloxãDNSãµãŒããŒãšããŠéžã°ãã5ã€ã®çç± https://note.com/infoblox/n/n7a44183dc9a4
çµãã
ä»åã¯DNSãµãŒããŒãç¹ã«ãã«ãªãŸã«ãã«ã€ããŠèª¿æ»ã解説ããŠã¿ãŸãããç§èªèº«ã¯ã€ã³ãã©ããã¯ã¢ããªã±ãŒã·ã§ã³åŽã®ITãšã³ãžãã¢ã§ãã®ã§ãééã£ãŠããéšåãããããšæããŸããæ°ã¥ããæ¹ã¯ã³ã¡ã³ããX(Twitter)ã§æããŠãã ããïŒãã©ããŒããåŸ ã¡ããŠãããŸãã
çŸåšãããã«ãªã§ã¯ITãšã³ãžãã¢ãåéããŠããŸããèå³ã®ããæ¹ã¯ãã²ãæ°è»œã«ãé£çµ¡ãã ããïŒ