FQDN TTL shorter than refresh time

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

FQDN TTL shorter than refresh time

L1 Bithead

I have a problem with some sites that uses DNS round robin as loadballancer.

As an examble:

vs-ssh.visualstudio.com

 

This has the TTL set to 300 sec, the PA's FQDN refresh is default 30 min.

So the firewall won't cache all IP's used in the round robin, because when it does a refresh the old value has timed-out

So the rule where I use the FQDN object fails periodic.

 

Is there a way to ignore the TTL value, not generally, but for indivually entries in the FQGN cache?

 

Rgds Knud

3 REPLIES 3

Cyber Elite
Cyber Elite

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClKbCAK

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

That was not exactly what I was asking for, I know you can change the refresh time, but that wont solve the problem.

 

I need to be able to configure an alternative TTL per FQDN so instead of having a 5 min TTL I could configure the PA to ignore the TTL in the DNS reply and configure the cache to 24 hours, but only for that entry.

Either DNS Proxy static entries or some external cron job to resolve names to IPs and then push results to Palo through API as often as needed.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011
  • 2311 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!