Setup guide

3. Click the Settings tab.
4. Uncheck the boxes for “Zone transfers” and “Recursion.”
5. Click Save.
If your site requires recursion, we recommend allowing recursive queries only from
trusted clients and not from any external networks. Zone transfers, if needed,
should be set up so that they only occur between trusted servers. This requires
manually editing the BIND configuration files, which is covered in the references.
Also note that using Server Admin after editing the BIND configuration files may
overwrite some changes.
Also, make sure that both forward and reverse zones are established and fully
populated. If this is not done, any Open Directory server using the DNS service will
not work correctly.
4.2 NTP, SNMP, and Macintosh Manager Services
Mac OS X Server includes basic network management services including network
time protocol (NTP) server software, simple network management protocol (SNMP)
software, and Macintosh Manager server software. Unless they are necessary, they
should be disabled. They are all disabled by default, but verification is
recommended.
The NTP software is an open-source implementation from http://www.ntp.org
and
allows Mac OS X Server to provide the current time to clients, so that they may
synchronize their clocks. Client systems specify their NTP server in the Date & Time
panel in System Preferences. If the NTP service is required, it should be enabled on
a single, trusted server within the local network. This service should otherwise be
disabled on all servers.
The SNMP software is also an open-source implementation and allows for other
systems to monitor and collect data on the state of a Mac OS X server. More
extensive documentation is available at the project web page at
http://net-snmp.sourceforge.net
. Use of this service is not recommended.
The Macintosh Manager server software allows Mac OS X Server to manage Mac OS
9 client systems and is described in Apple’sMac OS X Server User Management for
version 10.3.3 or later” manual. Use of Mac OS 9 on the network is not
recommended, and so this service should be disabled on all servers.
4.2.1 Disable the NTP, SNMP, and Macintosh Manager
Services
To disable these services:
31
UNCLASSIFIED