FAST-DNS Resolution Issues
50990
Created On 03/25/19 04:51 AM - Last Modified 05/16/24 03:40 AM
Symptom
Most of the CDN (Content Delivery Network) providers use FAST DNS switching, which in some cases causes DNS caching issues. This happens because of quick changing FQDNs at the CDN side.
Environment
- PAN-OS
- Firewall
- FQDN refresh
- FAST-DNS
Resolution
FQDN refresh timers are used to check the mapping between an IP address and a fully-qualified domain name. By default, Palo Alto Networks devices perform this check every 30 seconds.
- First workaround: Refer Change FQDN refresh timer to a minimum of 10 minutes.
- Second workaround: Refer Create a custom URL category for Akamai (CDN) servers FQDNs and add it to an allow security policy .
- Third workaround: Refer Upgrade to PAN-OS 9.0 for the built-in FQDN Refresh Enhancement feature .