Advanced Features of BIND

Most BIND implementations only use named to provide name resolution services or to act as an authority for a particular domain or sub-domain. However, BIND version 9 has a number of advanced features that, when properly configured, allow for a more secure and efficient DNS service.

CautionCaution
 

Some of these advanced features, such as DNSSEC, TSIG, and IXFR, should only be used in network environments with nameservers that support the features. If your network environment includes non-BIND or older BIND nameservers, check to see if a particular advanced feature is available before attempting to use it.

Do not assume another type of nameserver supports all of these features, as many do not.

All of the features discussed here are discussed in greater detail in the BIND 9 Administrator Reference Manual. See the Section called Additional Resources for places to find this manual.

DNS Protocol Enhancements

BIND supports Incremental Zone Transfers (IXFR), where slave nameserver will only download the updated portions of a zone modified on a master nameserver. The standard transfer AXFR process requires that the entire zone be transferred to each slave nameserver for even the smallest change. For very popular domains with very lengthy zone files and many slave nameservers, IXFR makes the notification and update process much less resource intensive.

Note that IXFR is only available if you are also using dynamic updating to make changes to master zone records. If you are manually editing zone files to make changes, AXFR will be used. More information on dynamic updating is available in the BIND 9 Administrator Reference Manual.

Multiple Views

Through the use of the view statement in /etc/named.conf, BIND allows you to configure a nameserver to answer queries for some clients in a different way than it answers them for others.

This is primarily used to deny particular types of DNS queries from clients outside of your network, while allowing those same queries from clients on the local network.

The view statement uses the match-clients option to match IP addresses or entire networks and give them special options and zone data.

Security

BIND supports a number of different methods to protect the updating and transfer of zones, on both master and slave nameservers:

IP version 6

BIND version 9 can provide nameservice in IP version 6 (IPv6) environments, through the use of A6 zone records.

If your network environment includes both IPv4 and IPv6 hosts, you should use the lwresd lightweight resolver daemon on your network clients. This daemon is essentially a very efficient, caching-only nameserver, which understands the new A6 and DNAME records used with IPv6. See the lwresd man page for more information.