Infoblox Exchange Cybersecurity Roadshow 2020 – Join us!
North America | Europe | Middle East/Africa | Asia-Pacific

DNS DHCP IPAM

Reply

Need to set NS record TTL to different value than zone default

Expert
Posts: 234
4539     0

Hi there,

 

I have been deploying DTC for a customer, it's all going well but we had an issue where the customer added a DTC LBDN and it had a TTL of 1 day, so subsequently got cached all around the Internet and completely circumvented the DTC healthcheck mechanism.

 

I have noticed that the TTL is inherited from the zone or grid if not explicitly set, so I suggested the customer set the default TTL on the zone to 10 minutes, so that when new entries are added they inherit the correct TTL (10 mins is what their previous GSLB solution used but we could arguably set it shorter or even to zero).

 

The problem now is that this has set the TTL to 10 minutes on the auto-generated NS records, and I can't override it because they are auto-generated.

 

As this is an external facing zone, I could really do with setting the NS record TTL to something longer (previously it was 1 day). If we did use a shorter default TTL for the LBDN's, this could potentially start to cause problems if it also affected the NS records.

 

I can't find a way to set the TTL on the NS records. Does anyone have any ideas?

 

Cheers,

 

Paul

 

Paul Roberts
PCN (UK) Ltd

All opinions expressed are my own and not representative of PCN Inc./PCN (UK) Ltd. E&OE

Re: Need to set NS record TTL to different value than zone default

GHorne Community Manager
Community Manager
Posts: 248
4540     0

There is no simple way to do this. But there is a kinda messy workaround using manual NS records.

 

If you all all the nameservers in the zone as 'stealth', the grid won't auto create any NS records. Then you just add manual NS records with the TTL that you want.

 

The drawback with this is you will have to manually maintain the NS records if you ever change nameservers for that zone.

Re: Need to set NS record TTL to different value than zone default

Expert
Posts: 234
4540     0

Yep I think that'll do it, a bit of sideways thinking required to come up with that idea, thanks.





Paul Roberts
PCN (UK) Ltd

All opinions expressed are my own and not representative of PCN Inc./PCN (UK) Ltd. E&OE

Re: Need to set NS record TTL to different value than zone default

Expert
Posts: 234
4540     0

Hmmm, I just tried this, I get an error:

 

"The NS group 'external' must have at least one non-stealth server assigned to it"

 

<scratches head>

 

Paul Roberts
PCN (UK) Ltd

All opinions expressed are my own and not representative of PCN Inc./PCN (UK) Ltd. E&OE
Showing results for 
Search instead for 
Do you mean 

Recommended for You