<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What Happens to FQDNs in a Security Policy when DNS Time-to-Live Expires and Device Cannot Reach in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-happens-to-fqdns-in-a-security-policy-when-dns-time-to-live/m-p/290678#M77161</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1289"&gt;@fatboy1607&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So the only time the firewall actually takes TTL into account is 9.0 and later, otherwise 8.1 and lower don't care about the records TTL. Within 9.0 you have an option of configuring both a Minimum FQDN refresh, along with a Stale Entry timeout. The Stale Entry setting is what you will want to look at and configure appropriately, as that's how long the firewall will continue to use its cache for FQDN objects if the DNS server isn't reachable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Prior to 9.0; the firewall doesn't take into account the TTL. It would refresh at whatever interval you have configured and if the DNS server became unreachable it would utilize it's cache entry until it was able to either refresh, the firewall was restarted, or the cache was cleared.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 30 Sep 2019 21:23:07 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2019-09-30T21:23:07Z</dc:date>
    <item>
      <title>What Happens to FQDNs in a Security Policy when DNS Time-to-Live Expires and Device Cannot Reach DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-happens-to-fqdns-in-a-security-policy-when-dns-time-to-live/m-p/290625#M77152</link>
      <description>&lt;P&gt;&amp;nbsp;What will happen in that case when DNS server becomes unreachable ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would destination server be unreachable ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Possible solution if DNS server gets unreachable.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2019 16:37:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-happens-to-fqdns-in-a-security-policy-when-dns-time-to-live/m-p/290625#M77152</guid>
      <dc:creator>fatboy1607</dc:creator>
      <dc:date>2019-09-30T16:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: What Happens to FQDNs in a Security Policy when DNS Time-to-Live Expires and Device Cannot Reach</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-happens-to-fqdns-in-a-security-policy-when-dns-time-to-live/m-p/290676#M77159</link>
      <description>&lt;P&gt;FYI:&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClbhCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClbhCAC&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2019 21:17:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-happens-to-fqdns-in-a-security-policy-when-dns-time-to-live/m-p/290676#M77159</guid>
      <dc:creator>myky</dc:creator>
      <dc:date>2019-09-30T21:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: What Happens to FQDNs in a Security Policy when DNS Time-to-Live Expires and Device Cannot Reach</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-happens-to-fqdns-in-a-security-policy-when-dns-time-to-live/m-p/290677#M77160</link>
      <description>&lt;P&gt;the fqdnobject will retain it's ild mapping even after the TTL expires if the dns server is unreachable at the time of expiry&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2019 21:22:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-happens-to-fqdns-in-a-security-policy-when-dns-time-to-live/m-p/290677#M77160</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-09-30T21:22:10Z</dc:date>
    </item>
    <item>
      <title>Re: What Happens to FQDNs in a Security Policy when DNS Time-to-Live Expires and Device Cannot Reach</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-happens-to-fqdns-in-a-security-policy-when-dns-time-to-live/m-p/290678#M77161</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1289"&gt;@fatboy1607&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So the only time the firewall actually takes TTL into account is 9.0 and later, otherwise 8.1 and lower don't care about the records TTL. Within 9.0 you have an option of configuring both a Minimum FQDN refresh, along with a Stale Entry timeout. The Stale Entry setting is what you will want to look at and configure appropriately, as that's how long the firewall will continue to use its cache for FQDN objects if the DNS server isn't reachable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Prior to 9.0; the firewall doesn't take into account the TTL. It would refresh at whatever interval you have configured and if the DNS server became unreachable it would utilize it's cache entry until it was able to either refresh, the firewall was restarted, or the cache was cleared.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2019 21:23:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-happens-to-fqdns-in-a-security-policy-when-dns-time-to-live/m-p/290678#M77161</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-09-30T21:23:07Z</dc:date>
    </item>
  </channel>
</rss>

