Hello
We have FortiOS 7.0.12, NP7.
We need to reduce ttl of DNS sessions to something below 120s.
Using config system session-ttl for UDP 53 with a value under 120 shows this warning message:
Warning: TTL(60) sent to NPU is limited to 120 seconds, software TTL is unchanged.
The question are:
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
There is no way to set the session timeout (TTL) of UDP 53 to less than 120 seconds on NP7 FortiOS 7.0.x. This is because the NPU hardware has a minimum TTL of 120 seconds for UDP 53 sessions.
If you set the TTL to 30 seconds in the kernel and leave it at 120 seconds in the NPU, the NPU will continue to use a TTL of 120 seconds for all UDP 53 sessions. I mean some DNS sessions may last longer than 30 seconds, even if the kernel is configured to use a shorter TTL...
And yup, there are a few potential side effects of setting the DNS TTL to 30 seconds in the kernel - increased network traffic, increased load on the DNS server, and reduced DNS cache hit rate.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.