[dns-operations] DNS prefetching,	DLV and cheap NAT router state table overflow
    Florian Weimer 
    fw at deneb.enyo.de
       
    Fri Oct  1 08:05:03 UTC 2010
    
    
  
* James Cloos:
> One thing which helps is to set unbound's timeout to something
> reasonable for an edge lan.  (The default of .2 s is too short.)
>
> Start with at least 5s:
>
> 	jostle-timeout: 5000
>
> That will keep unbound from flooding most of the time.
This seems to make matters worse because Unbound generates more UDP
flows as a result.  (If Unbound aborts the query, the corresponding
state does not magically disappear from the NAT device.)
    
    
More information about the dns-operations
mailing list