This article provide the method how to check TTL value of DNS proxy Cache on SRX platform, and also explain that this value is different from the DNS entry for security policy when the initial TTL is lower than 16.
Some domains use very low DNS TTL values that may be under 16. When FQDN(s) are used for security policy, the SRX always cache the TTL value as 16 if the resolved DNS contains a TTL value under 16. (For more details, please check KB32397 - [SRX] Packets dropped by security policy due when TTL value is low and FQDN is used in security policies [juniper.net] (login required) However, when SRX is being used as DNS proxy, the TTL value used in the DNS proxy cache will be the received value including TTL that are lower than 16.
Regarding how to set DNS proxy on SRX, please check KB27492- [SRX] Configuration example - SRX Services Gateway used as a DNS proxy [juniper.net] . Topology: PC(client)------SRX--------DNS_server Verification: DNS Proxy Server Usage
root# run show system services dns-proxy cache | match "css" www.cssxxxx.com. 8 A IN 10.75.252.34
> show security dns-cache dns-name www.cssxxxx.com DNS Name: www.cssxxxx.com Address Family: IPv4, TTL: 14