cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
679
Views
0
Helpful
1
Replies

ASA access to FQDN

Sergey Prishchepa
Spotlight
Spotlight

On the ASA 5525-X is configured to access FQDN. Everything works well, but there is one feature. Lifetime matching FQDN and ip default 21 min., Obtained 21 minutes after ASA updates the information, but she did it for a minute and all this time blocked traffic. TTL for dns can be increased, but how to reduce this minute interval, preferably up to 1 second?

1 Reply 1

David White
Cisco Employee
Cisco Employee

Hi Sergey,

You cannot lower the ASA's DNS aging timeout below 1 minute.  Note that each time the timeout occurs, the ASA must refresh the DNS entry, and then update and re-compile the ACLs (where the FQDN name is used).  If you had multiple entries expiring every second, the policy would constantly be changing and the ASA would be constantly re-compiling the ACLs (ie: the Security Policy).

Hope this helps,


David.

Review Cisco Networking products for a $25 gift card