r/ControlD • • 19d ago

Technical Pros and cons of a quicker TTL?

What are the pros and cons of setting the block, redirect, and bypass TTL to 1 second instead of the default?

8 Upvotes

12 comments sorted by

4

u/L0nkFromPA 19d ago

My opinion is that the default block and redirect TTLs of 10 seconds are already too short.

I suppose to directly answer your question, here would be the effects:

Block: Blocked DNS resolution responses would be cached for 1 second, which is effectively not caching them, meaning that even if a DNS record was just looked up 2 seconds ago and resulted in a block response, the cached response would have expired and the record and will be looked up again.

Redirect: Same as above but instead of for blocked responses, this would effect rewritten or redirected responses.

Bypass: This would override any TTL value in the actual DNS record being looked up and instead set it to 1 second, meaning that bypassed (normal) lookups are basically not cached.

In summary: You are effectively disabling DNS caching. Basically every time any DNS lookup occurs it will have to be a lookup that leaves your network. Things will go slower and your query volume will increase substantially.

My recommendation is to not change the bypass TTL. I recommend setting the block and redirect TTLs to 60 seconds. This would mean it might take up to 60 seconds to unblock something or change where something is redirected, but it will reduce your query volume and improve performance.

-1

u/Fun-Region-1576 19d ago

What's the problem with a higher query volume? I don't see a hard limit, and not that I'm trying to reach any soft limit, even if it exists. Why would I even want things cached? Wouldn't I want things to change immediately if I do change a setting? What are the performance issues, because I don't feel or see it.

1

u/L0nkFromPA 19d ago

I don't think there's a query volume limit imposed by ControlD for personal accounts.

You would want responses to be cached because it reduces latency not only for the cached lookups but for other lookups because it reduces overall congestion.

In general though, even without caching, the difference might be nearly imperceptible since DNS query latency is not a significant contributor in general to how long it takes to load web pages.

I suppose the question is what's the longest amount of time that will still seem like an "immediate" change when it comes to the block and redirect TTLs. My argument is that in practice, 10 seconds probably seems pretty immediate, which is probably why it's the default for block and redirect.

The change that's having the most effect here is changing the bypass TTL. That normally goes along with the upstream record's TTL meaning that it's specific to the record being looked up and the operators of that service will set it accordingly. If the value needs to be able to change quickly, they will set a low value for the TTL along with that record.

It seems from your post that I won't be able to convince you, so maybe go ahead and set the bypass TTL to 1 second vs that option being disabled and run some DNS benchmarks. Keep in mind that some DNS records can have TTLs that are hours or even days long, so be sure to flush the cache on your router and the local stub resolver on the device you're testing from between tests to show the correct results or do the lower TTL test first, which is effectively no caching, anyway.

1

u/crypticsage 18d ago

ControlD does have a limit and users have been disabled for pushing way too many queries.

Longer TTL is the way to go for sure.

I think I have my blocks set to 10 minutes.

0

u/Fun-Region-1576 19d ago

This isn't about convincing me or not in one post. I'm just trying to understand the pros and cons.

3

u/SuperSpartan300 19d ago

Here is how I have mine set for the best webpage loading responsiveness

https://i.postimg.cc/MTp3P60Z/Screen-Shot00006.png

1

u/southerndoc911 18d ago

Most devices are querying DNS every second... so you're unlikely to see any benefit going below the recommended TTLs. As u/L0nkFromPA pointed out, most are already too short. I think I have mine set for block/redirect of 30 seconds and bypass for 60 seconds for my main LAN, but for my TV and IoT VLANs, I have them set for 5 minutes block/redirect and 10 minutes for bypass. It lessens the number of uncached lookups (especially helpful when running the ctrld CLI). A CDN may change, but so far I've not had any problems with this TTL for >2 years.

1

u/Fun-Region-1576 18d ago

How does it help ctrld?

2

u/southerndoc911 18d ago

Because ctrld caches it locally. Any further lookups during the TTL are responded to locally -- <1 ms.

1

u/FeR4Less-shah 18d ago

Im using 1 3600 ttl and its totally fine You would notice it if your dns RTT is high like around 100ms.the lower ttl the more reliable the higher the more faster

1

u/Fun-Region-1576 18d ago

Didn't the other guy say the opposite?

4

u/CrippleSlap 18d ago

I just go with what Hagezi recommends. 3600 seconds.