[dns-operations] DNS prefetching, DLV and cheap NAT router state table overflow

Florian Weimer fw at deneb.enyo.de
Fri Oct 1 08:05:03 UTC 2010


* James Cloos:

> One thing which helps is to set unbound's timeout to something
> reasonable for an edge lan.  (The default of .2 s is too short.)
>
> Start with at least 5s:
>
> 	jostle-timeout: 5000
>
> That will keep unbound from flooding most of the time.

This seems to make matters worse because Unbound generates more UDP
flows as a result.  (If Unbound aborts the query, the corresponding
state does not magically disappear from the NAT device.)



More information about the dns-operations mailing list