Every FQDN had its Expire cache by TTL disabled?
Guru Member
USG FLEX 700H V1.36(ABZI.0)
Some how over 400 FQDN had its Expire cache by TTL to disable so I'm thinking something nebula changed it?
Not that this is a problem its just I should be the one to change it.
So a backup config I have a copy the FQDN TTL back in
so like this is a snippet when it was fine
/ object address-object address "stickyadstv_com" "type" "fqdn" "*.stickyadstv.com" "expire_ttl" "true" / object address-object address "amazonaws_com" "type" "fqdn" "*.amazonaws.com" "expire_ttl" "false" / object address-object address "gstatic_com" "type" "fqdn" "*.gstatic.com" "expire_ttl" "true"
then
/ object address-object address "stickyadstv_com" "type" "fqdn" "*.stickyadstv.com" / object address-object address "amazonaws_com" "type" "fqdn" "*.amazonaws.com" / object address-object address "gstatic_com" "type" "fqdn" "*.gstatic.com"
You can see some how the true and false expire ttl got removed
All Replies
-
Hi @PeterUK
This is a side effect when disabling/enabling the manual link VPN entry. This is an unexpected behavior, and we are checking on this. I will update you once I get further information.
Zyxel Melen0 -
Thanks for the reply
Hmm…odd how something unrelated cold impact the other…I guess changing one thing like manual link VPN entry uploads the whole config changes from nebula?
0 -
Yes. Please allow me to correct that this is not an unexpected behavior. When disable manual link VPN on Nebula, to ensure the configuration consistency and works, Nebula will push all configuration. And because currently the address object doesn't support "Expire cache by TTL", so the Nebula push the configuration with "Expire cache by TTL" disabled.
Zyxel Melen0 -
I think its the other way round when Nebula push the configuration without the
"expire_ttl"
option for true or false its default is true but the local UI shows false but really its true which would explain why *.amazonaws.com was having a problem.
so really if your going to do Nebula with local UI you really should include the config correctly or add all of the options local UI has to Nebula to avoid this from happening.
Thanks
strange things happen with doing trinary😉
0 -
Hi @PeterUK
Yes, Nebula will have the Expire cache by TTL option for the FQDN objects in future release.
ETA is about 2026 Q2. Please follow the Nebula release category for future support news.
Zyxel Melen1 -
Great thanks
0
Categories
- All Categories
- 441 Beta Program
- 2.9K Nebula
- 208 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.4K Security
- 529 USG FLEX H Series
- 333 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.3K Wireless
- 51 Wireless Ideas
- 6.9K Consumer Product
- 292 Service & License
- 461 News and Release
- 90 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.7K FAQ
- 34 Documents
- 86 About Community
- 99 Security Highlight
Zyxel Employee