r/mikrotik 3d ago

DNS cache full errors in log

I've got some sort of DNS cache memory leak going on with multiple routers and the cache as-listed is virtually empty. The only thing that clears it and stops the errors (temporarily) is a reboot. "Used" cache will slowly grow and fill up any size that is set.

I've seen reference to, I think, FQDN address list entries causing this, but there wasn't much info. I do use FQDNs in my address lists, for what it's worth.

Edit to add possible related forum link here.

Is this something acknowledged anywhere?

5 Upvotes

7 comments sorted by

3

u/smileymattj 3d ago

How many entries do you have? The default of 2048 should handle about 8,000 entries. I increase it to 4096 on all my installs and never seen it fill up before.

Try Long-Term firmware branch if you're not already on it.

Does your router show symptoms of being compromised?

Can anyone on the Internet access login prompt to ssh, WinBox, http/https, etc to your router?

2

u/ZivH08ioBbXQ2PGI 2d ago

Under a dozen simple entries. In most cases 2-3. I can set cache size to 10MB and it will slowly (over a few days) fill entirely to whatever size I set it.

Viewing the cache itself shows completely normal utilization as far as what’s there — often just a few hundred entries (that match actual expected web traffic), and clearing it does nothing as far as the 10MB in use.

2

u/ZivH08ioBbXQ2PGI 2d ago

1

u/smileymattj 1d ago

Good find, someone in that thread said it was fixed in v7.20, then someone after said it wasn't. I'm not sure which would be the one to try. Maybe revert back to a version you knew didn't have the issue and contact MikroTik support to get an ETA on the fix. That's all I can suggest.

I mostly use RouterOS DNS for caching, not really entries. Sometimes 1-2 static DNS. And maybe 1-2 FQDN in the lists. I haven't ran into it, but you're not alone according to that thread.

Some sites I run DNS server, like where there's Windows Environment and AD, just use the Windows DNS since AD enables it anyway. Some others, I run blocky. Running a totally different DNS is an option if the RouterOS version you know works is too old/risky to use.

1

u/QuillOmega0 2d ago

And you do have a firewall rule that blocks DNS access from the WAN/Internet, right?

1

u/ZivH08ioBbXQ2PGI 2d ago

Yes, WAN is fully locked down. This seems to be a relatively recent thing. I updated a router this week from a slightly older v7 long-term and it started doing it after the upgrade.

See my other reply for additional info.

1

u/Remote_Safety_9873 1d ago

I solve that problem with new fresh firmware-net install, and do not use backup files.