Every FQDN had its Expire cache by TTL disabled?
Guru Member
USG FLEX 700H V1.36(ABZI.0)
Some how over 400 FQDN had its Expire cache by TTL to disable so I'm thinking something nebula changed it?
Not that this is a problem its just I should be the one to change it.
So a backup config I have a copy the FQDN TTL back in
so like this is a snippet when it was fine
/ object address-object address "stickyadstv_com" "type" "fqdn" "*.stickyadstv.com" "expire_ttl" "true" / object address-object address "amazonaws_com" "type" "fqdn" "*.amazonaws.com" "expire_ttl" "false" / object address-object address "gstatic_com" "type" "fqdn" "*.gstatic.com" "expire_ttl" "true"
then
/ object address-object address "stickyadstv_com" "type" "fqdn" "*.stickyadstv.com" / object address-object address "amazonaws_com" "type" "fqdn" "*.amazonaws.com" / object address-object address "gstatic_com" "type" "fqdn" "*.gstatic.com"
You can see some how the true and false expire ttl got removed
All Replies
-
Hi @PeterUK
This is a side effect when disabling/enabling the manual link VPN entry. This is an unexpected behavior, and we are checking on this. I will update you once I get further information.
Zyxel Melen0 -
Thanks for the reply
Hmm…odd how something unrelated cold impact the other…I guess changing one thing like manual link VPN entry uploads the whole config changes from nebula?
0 -
Yes. Please allow me to correct that this is not an unexpected behavior. When disable manual link VPN on Nebula, to ensure the configuration consistency and works, Nebula will push all configuration. And because currently the address object doesn't support "Expire cache by TTL", so the Nebula push the configuration with "Expire cache by TTL" disabled.
Zyxel Melen0 -
I think its the other way round when Nebula push the configuration without the
"expire_ttl"
option for true or false its default is true but the local UI shows false but really its true which would explain why *.amazonaws.com was having a problem.
so really if your going to do Nebula with local UI you really should include the config correctly or add all of the options local UI has to Nebula to avoid this from happening.
Thanks
strange things happen with doing trinary😉
0
Categories
- All Categories
- 439 Beta Program
- 2.8K Nebula
- 202 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.3K Security
- 515 USG FLEX H Series
- 328 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.3K Wireless
- 49 Wireless Ideas
- 6.9K Consumer Product
- 288 Service & License
- 458 News and Release
- 90 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.3K FAQ
- 34 Documents
- 85 About Community
- 97 Security Highlight
Zyxel Employee