# DNS Express Off-Box IXFR Takes About 20 Seconds

**URL:** <https://community.f5.com/t/dns-express-off-box-ixfr-takes-about-20-seconds/73609>\
**Category:** Technical Forums\
**Tags:** application-delivery\
**Created:** [December 6, 2023, 5:37am UTC](https://community.f5.com/t/dns-express-off-box-ixfr-takes-about-20-seconds/73609 "2023-12-06T05:37:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![HosseinAmery](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/hosseinamery/32/13044_2.png) [@HosseinAmery](https://community.f5.com/u/HosseinAmery)\
**Post date:** [December 6, 2023, 5:37am UTC](https://community.f5.com/t/dns-express-off-box-ixfr-takes-about-20-seconds/73609/1 "2023-12-06T05:37:05Z")

</div>

Hello.

I have 2 BIG-IP boxes in a HA cluster running (BIG-IP 17.0.0.2 Build 0.0.2 Point Release 2). I’ve set up DNS Express for an off-box BIND server. AXFR works great, but upon making a change in BIND zone file, it’ll take almost 20 seconds for IXFR to replicate the change to DNS Express. I changed the “dnsexpress.xfrnotifydelay” to 0, but nothing happened. Is that 20 seconds the normal behavior of BIGIP for IXFR or I’m missing something?

Thank you.

---

<div class="post-metadata">

**Author:** ![zamroni777](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/zamroni777/32/1473_2.png) [@zamroni777](https://community.f5.com/u/zamroni777)\
**Post date:** [December 6, 2023, 9:59am UTC](https://community.f5.com/t/dns-express-off-box-ixfr-takes-about-20-seconds/73609/2 "2023-12-06T09:59:17Z")

</div>

is there any error message in the /var/log ?  
ihealth may provide some analysis too

---

<div class="post-metadata">

**Author:** ![F5\_Design\_Engineer](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/f5_design_engineer/32/2479_2.png) [@F5\_Design\_Engineer](https://community.f5.com/u/F5_Design_Engineer)\
**Post date:** [December 8, 2023, 4:20pm UTC](https://community.f5.com/t/dns-express-off-box-ixfr-takes-about-20-seconds/73609/3 "2023-12-08T16:20:31Z")

</div>

Hi HosseinAmery,

Frequent DNS Express zone transfers prevent updated zone data from becoming available.

DNS Express performs a zone transfer more frequently than every 15 seconds.

Have you tried using **dnsxdump in BASH mode**

The&nbsp; **dnsxdump** utility displays the DNS Express database information.

 ![F5_Design_Engineer_0-1702050108082.png](https://d20hrnpixdzcsd.cloudfront.net/original/2X/9/90db7bcd5965093effe8584d2c2f7576818f6c93.png)

The&nbsp; **dnsxdump&nbsp;utility outputs directly to the console. If you have a large number of zones, or zone resource records, you can redirect the output to a text file for later review in your preferred text editor.**

For example, to redirect the output to&nbsp; **/var/tmp/my\_zones.txt&nbsp;you would type the following command:**

**dnsxdump \> /var/tmp/my\_zones.txt**

To see or troubleshoot zone transfers, we can refer to the&nbsp;_/var/log/ltm&nbsp;log file. A quick examination of the log should show a successful zone transfer in the lab:_

> ```auto
> <strong><span class="">#tail -100 /var/log/ltm <span class="">| grep zxfrd</span></span></strong>
> 
> ```
> 
> Can you also check
> 
> **dnsexpress.notifyport \<value\>**
> 
> **dnsexpress.xfrnotifydelay \<value\>**
> 
> default value is 5 seconds
> 
> root@(F5-Design\_Engg02)(cfg-sync Standalone)(Active)(/Common)(tmos)# **list sys db dnsexpress.xfrnotifydelay  
> sys db dnsexpress.xfrnotifydelay {  
> value “5”  
> }**
> 
> This DB variable controls the delay in seconds between the time the **zxfrd process receives a DNS Notify message from the authoritative DNS server and the time it schedules an AXFR/IXFR.  
> Note: _This does not mean the zone transfer occurs immediately after this delay as the start of the zone transfer also depends on the load on the BIG-IP system, the authoritative DNS server and the network between them; as well as the size of the zone transfer._**
> 
> The **zxfrd process manages zone transfers and writes to the zone database files. When it receives an update request, it initiates a zone transfer to the authoritative DNS server. The results of the zone transfer are then committed to the zone DB.  
> The zxfrd process may restart and produce a core file if:  
> An active zone transfer is interrupted  
> The interruption is between the BIG-IP system and the DNS server  
> The interruption is caused by a network outage  
> The zxfrd process may also produce a core file and restart when:  
> Importing a zone file that contains a WINS RR**
> 
> The zxfrd process manages zone transfers and writes to the zone database files.  
> **zxfrd listens on ::1:5353  
> Zone transfer uses tcp:53**
> 
> search for
> 
> **tailf /var/log/gtm | grep zxfrd  
> tmsh show ltm dns dns-express**
> 
> If DNS Express not initiating Zone Transfer after receiving DNS Notify Please Verify Notify TSIG option is enabled (by default) in the DNS Express zone and waits for the TSIG key (transaction signature) to be sent from the Authoritative DNS Server
> 
> Else  
> Disable the Verify Notify TSIG option on the DNS zone. With this configuration, DNS Express can process a NOTIFY message without a TSIG key, even when a subsequent zone transfer requires a TSIG key.
> 
> [myF5](https://my.f5.com/manage/s/article/K15468995)
> 
> K45411181: Configuring DNS Express using tmsh
> 
> [myF5](https://my.f5.com/manage/s/article/K45411181)
> 
> Hope this Helps
> 
> 🙏
> 
> ![HaveahappydayYayGIF.gif](https://d20hrnpixdzcsd.cloudfront.net/original/2X/f/fa580329f80f061d0302446a039e531cd1b8b5a0.gif)

---

<div class="post-metadata">

**Author:** ![Mohamed\_Ahmed\_Kansoh](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/mohamed_ahmed_kansoh/32/10886_2.png) [@Mohamed\_Ahmed\_Kansoh](https://community.f5.com/u/Mohamed_Ahmed_Kansoh)\
**Post date:** [December 9, 2023, 1:02pm UTC](https://community.f5.com/t/dns-express-off-box-ixfr-takes-about-20-seconds/73609/4 "2023-12-09T13:02:38Z")

</div>

Hi&nbsp;&nbsp; @HosseinAmery &nbsp;,

I havn’t measure the time exactily for the IXFR but I noticed yes it took some time to replicate the changes in Bind to bigip DNS express zones.

But I will recommend somthing else.

Make sure that you added this&nbsp;**also-notify&nbsp;statement in the BIND (master) configuration file beside \*\*allow-transfer&nbsp;statement as well.**

 

**here this BIND standard configuration statements :&nbsp;[https://www.zytrax.com/books/dns/ch7/xfer.html#also-notify](https://www.zytrax.com/books/dns/ch7/xfer.html#also-notify)\*\***

have a look on :

1. [allow-notify](https://www.zytrax.com/books/dns/ch7/xfer.html#allow-notify)

2. [allow-transfer](https://www.zytrax.com/books/dns/ch7/xfer.html#allow-transfer)

3. [allow-update](https://www.zytrax.com/books/dns/ch7/xfer.html#allow-update)

4. [also-notify](https://www.zytrax.com/books/dns/ch7/xfer.html#also-notify)

5. [notify](https://www.zytrax.com/books/dns/ch7/xfer.html#notify)
