User Tools

Site Tools


pfsense:dns:troubleshooting:slow_dns_response

This is an old revision of the document!


PFSense - DNS - Troubleshooting - Slow DNS Response

Navigate to Diagnostics → Command Prompt.

unbound-control -c /var/unbound/unbound.conf stats_noreset | egrep 'total.num|cache.count'

returns:

total.num.queries=1297
total.num.queries_ip_ratelimited=0
total.num.cachehits=1026
total.num.cachemiss=271
total.num.prefetch=96
total.num.expired=88
total.num.recursivereplies=271
msg.cache.count=1552
rrset.cache.count=3277
infra.cache.count=3255
key.cache.count=132

NOTE: This combines the output of:

  • unbound-control -c /var/unbound/unbound.conf stats_noreset | grep total.num
  • unbound-control -c /var/unbound/unbound.conf stats_noreset | grep cache.count

Output is:

  • num.queries: number of queries received by thread.
  • num.cachehits: number of queries that were successfully answered using a cache lookup.
  • num.cachemiss: number of queries that needed recursive processing.
  • num.prefetch: number of cache prefetches performed.
    • This number is included in cachehits, as the original query had the unprefetched answer from cache, and resulted in recursive processing, taking a slot in the requestlist.
    • Not part of the recursivereplies (or the histogram thereof) or cachemiss, as a cache response was sent.
  • num.zero_ttl: number of replies with ttl zero, because they served an expired cache entry.
  • num.recursivereplies: The number of replies sent to queries that needed recursive processing.
    • Could be smaller than threadX.num.cachemiss if due to timeouts no replies were sent for some queries.
  • msg.cache.count: The number of items (DNS replies) in the message cache.
  • rrset.cache.count: The number of RRsets in the rrset cache. This includes rrsets used by the messages in the message cache, but also delegation information.
  • infra.cache.count: The number of items in the infra cache.
    • These are IP addresses with their timing and protocol support information.
  • key.cache.count: The number of items in the key cache.
    • These are DNSSEC keys, one item per delegation point, and their validation status.
pfsense/dns/troubleshooting/slow_dns_response.1612110829.txt.gz · Last modified: 2021/01/31 16:33 by peter

Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki