Skip to content

DNS Firewall FAQ

Last updated View as MarkdownAgent setup

Consider the answers for frequently asked questions about Cloudflare DNS Firewall.

How does DNS Firewall choose a backend nameserver to query upstream?

DNS Firewall alternates between a customer's nameservers, using an algorithm that is more likely to send queries to the faster upstream nameservers than slower nameservers.

How long does DNS Firewall cache a stale object?

DNS Firewall sets cache longevity according to allocated memory.

As long as there is enough allocated memory, Cloudflare does not clear items from the cache forcefully, even when the TTL expires. This feature allows Cloudflare to serve stale objects from cache if your nameservers are offline.

Does the DNS Firewall cache SERVFAIL?

Yes. SERVFAIL is treated like any other negative answer for caching purposes. The default TTL is 30 seconds. You can set a different negative cache TTL on your cluster in the Cloudflare dashboard, or via the API (negative_cache_ttl parameter).

Does DNS Firewall support EDNS Client Subnet (ECS)?

Yes. Often, DNS providers want to see a client's IP via EDNS Client Subnet (ECS) (RFC 7871 ↗︎) because they serve geographically specific DNS answers based on the client's IP. With EDNS Client Subnet enabled, the DNS Firewall will forward the client's IP subnet along with the DNS query to the upstream nameserver.

When EDNS is enabled, the DNS Firewall gives out the geographically correct answer in cache based on the client IP subnet. To do this, the DNS Firewall segments its cache. For example:

  1. A resolver says it is looking for an answer for client 192.0.2.0/24.
  2. The DNS Firewall will proxy the request to the upstream nameserver for the answer.
  3. The DNS Firewall will cache the answer from the upstream nameserver, but only for that /24.
  4. 203.0.113.0/24 now asks the same DNS question and the answer is again returned from the upstream nameserver instead of the cache.

Some resolvers might not be sending any EDNS data. When you enable ECS fallback on your cluster in the Cloudflare dashboard — or set the ecs_fallback parameter to true via the API — DNS Firewall will forward the IP subnet of the resolver instead, only if there is no EDNS data present in the incoming DNS query.

Does DNS Firewall cache negative answers?

Yes. The default TTL is 30 seconds. You can configure the negative cache TTL on your cluster in the Cloudflare dashboard, or via the API (negative_cache_ttl parameter). This will affect the TTL of responses with status REFUSED, NXDOMAIN, or SERVFAIL.

How can I set PTR records for nameserver hostnames?

To set up PTR records for the DNS Firewall cluster IPs that point to your nameserver hostnames, use the following API endpoints:

Why do I see inconsistent responses for the same ECS subnet from different locations?

DNS Firewall maintains a separate cache at each Cloudflare data center. When two resolvers send the same query for the same ECS subnet but reach different Cloudflare data centers, they may receive different responses if one data center has the answer cached from an earlier upstream query and the other does not. If your upstream nameserver returns non-deterministic answers for a given ECS subnet — for example, returning different address sets on repeated queries — each data center caches whichever answer it received, resulting in inconsistent responses across Cloudflare locations.

To get consistent results, ensure your upstream nameserver returns the same answer for a given ECS subnet on every query. If geographic routing is not required, you can disable ECS on your DNS Firewall cluster to use a single cache that is not segmented by client subnet.

What happens when the per-data-center rate limit is exceeded?

When the configured rate limit for a data center is exceeded, DNS Firewall stops forwarding queries to your upstream nameservers at that location for a short period. During this time, DNS Firewall continues to serve responses from its cache. Queries for records that are not in the cache, or whose cached TTL has expired, return REFUSED.

The rate limit applies independently at each Cloudflare data center. Exceeding the limit at one location does not affect query forwarding at other locations.

Was this helpful?