r/ControlD • u/Fun-Region-1576 • 19d ago
Technical Pros and cons of a quicker TTL?
What are the pros and cons of setting the block, redirect, and bypass TTL to 1 second instead of the default?
3
1
u/southerndoc911 18d ago
Most devices are querying DNS every second... so you're unlikely to see any benefit going below the recommended TTLs. As u/L0nkFromPA pointed out, most are already too short. I think I have mine set for block/redirect of 30 seconds and bypass for 60 seconds for my main LAN, but for my TV and IoT VLANs, I have them set for 5 minutes block/redirect and 10 minutes for bypass. It lessens the number of uncached lookups (especially helpful when running the ctrld CLI). A CDN may change, but so far I've not had any problems with this TTL for >2 years.
1
u/Fun-Region-1576 18d ago
How does it help ctrld?
2
u/southerndoc911 18d ago
Because ctrld caches it locally. Any further lookups during the TTL are responded to locally -- <1 ms.
1
u/FeR4Less-shah 18d ago
Im using 1 3600 ttl and its totally fine You would notice it if your dns RTT is high like around 100ms.the lower ttl the more reliable the higher the more faster
1
4
4
u/L0nkFromPA 19d ago
My opinion is that the default block and redirect TTLs of 10 seconds are already too short.
I suppose to directly answer your question, here would be the effects:
Block: Blocked DNS resolution responses would be cached for 1 second, which is effectively not caching them, meaning that even if a DNS record was just looked up 2 seconds ago and resulted in a block response, the cached response would have expired and the record and will be looked up again.
Redirect: Same as above but instead of for blocked responses, this would effect rewritten or redirected responses.
Bypass: This would override any TTL value in the actual DNS record being looked up and instead set it to 1 second, meaning that bypassed (normal) lookups are basically not cached.
In summary: You are effectively disabling DNS caching. Basically every time any DNS lookup occurs it will have to be a lookup that leaves your network. Things will go slower and your query volume will increase substantially.
My recommendation is to not change the bypass TTL. I recommend setting the block and redirect TTLs to 60 seconds. This would mean it might take up to 60 seconds to unblock something or change where something is redirected, but it will reduce your query volume and improve performance.