A Cisco router is a modest DNS citizen: a resolver for its own management traffic, a place for a few static host mappings, and — if you ask it — a small caching server for a branch. Knowing exactly how much it does (and the one setting that hangs your CLI for 30 seconds) keeps name resolution out of your troubleshooting. The MikroTik twin, with DoH and FQDN firewalling, is MikroTik: DNS, DoH & FQDN filtering.
DNS on IOS splits cleanly in two. Most of the time the router is a client — it resolves ntp.example.com, a TACACS hostname, or the name you typed at the CLI. Occasionally you make it a server: static ip host entries, or a lightweight caching resolver for a small site that has no dedicated DNS box.
The honest framing: a router is not a DNS server. ip dns server is fine for a handful of hosts at a branch; anything real belongs on BIND, Unbound, Pi-hole, or AD DNS. This post covers the resolver you always use, the static entries you'll actually need, the caching server where it makes sense, and the ip domain lookup behaviour that has cost everyone 30 seconds of staring at a frozen terminal.
01
By default IOS tries to resolve any unrecognised word you type as a hostname — via broadcast. That's the frozen-terminal bug. Fix the resolver config and the CLI behaviour in the same breath.
# Point the router at real resolvers and give it a default domain. R1(config)# ip name-server 1.1.1.1 9.9.9.9 R1(config)# ip domain name lab.lan # appended to unqualified names R1(config)# ip domain lookup # enable resolution (on by default) # Pin lookups to a stable source so ACLs/logs see one IP (same # discipline as AAA/syslog source-interface). R1(config)# ip domain lookup source-interface Loopback0
Type a command wrong (say you fat-finger sh ip rote) and IOS decides the unknown word is a hostname. With no name-server set it broadcasts for it and the CLI blocks until the attempt times out — the classic "I can't type anything" freeze. Two cures: on boxes that don't need DNS, no ip domain lookup; on boxes that do, set line vty 0 4 / transport preferred none so a mistyped command isn't treated as a telnet target. If you're stuck mid-hang, Ctrl+Shift+6 aborts it.
02
A few names you don't want to depend on DNS for — the syslog box, the NTP master, a jump host. ip host is the router's /etc/hosts and always wins over the resolver.
R1(config)# ip host syslog.lab.lan 10.0.0.5 R1(config)# ip host ntp.lab.lan 10.0.0.1 R1(config)# ip host v6host.lab.lan 2001:db8:10::5 # AAAA # Now you can reference names in config and they survive a DNS outage. R1(config)# logging host syslog.lab.lan R1(config)# ntp server ntp.lab.lan
Infrastructure the router depends on to function — its logging collector, NTP source, AAA server — should resolve even when DNS is down, because those are exactly the services you lean on during an outage. Pin them with ip host. Keep dynamic resolution for everything else.
03
At a branch with no DNS box, the router can answer clients directly: serve its static entries, cache recursive answers, and forward the rest upstream. Keep expectations small.
# Turn the router into a DNS server. It answers 'ip host' entries, # caches answers it recurses, and forwards misses to the name-servers. R1(config)# ip dns server R1(config)# ip name-server 1.1.1.1 9.9.9.9 # upstream for cache misses # Hand this router's own LAN IP to clients as their DNS server via DHCP. R1(config)# ip dhcp pool LAN R1(dhcp-config)# network 10.10.10.0 255.255.255.0 R1(dhcp-config)# dns-server 10.10.10.1 # = this router R1(dhcp-config)# domain-name lab.lan
If the router has a public interface and ip dns server is on, it will happily answer recursive queries from the internet — making you a free amplifier for DNS reflection DDoS and leaking internal names. Restrict UDP/TCP 53 to inside sources with an ACL on the WAN interface, the same way you'd lock down the MikroTik resolver. A branch router should answer its own clients, nobody else.
R1(config)# ip access-list extended WAN-IN R1(config-ext-nacl)# deny udp any any eq domain R1(config-ext-nacl)# deny tcp any any eq domain R1(config-ext-nacl)# permit ip any any # (rest of your edge policy) R1(config)# interface Gi0/0 R1(config-if)# ip access-group WAN-IN in
04
Prove resolution works, read the cache, and watch a live query. All read-only.
R1# show hosts # static + cached entries, TTLs R1# show ip dns view # server/forwarder state R1# ping ntp.lab.lan # resolves, then pings R1# show hosts summary R1# debug domain # lab box only — watch queries live R1# clear host * # flush the cache when testing
| Symptom | Likely cause |
|---|---|
| CLI freezes on a typo | ip domain lookup on + no name-server → fix per §01 |
| Names resolve from router, not clients | DHCP dns-server points at the wrong IP, or ip dns server off |
| Resolution works, then stops | Upstream unreachable; cache expired — check ip name-server reachability |
| Internal names leak / abuse reports | Open resolver — ACL port 53 inbound (§03) |
Takeaways
ip name-server — and either disable ip domain lookup or set transport preferred none so typos don't freeze the CLI.ip domain lookup source-interface to a loopback, the same discipline as AAA/syslog/NTP.ip host entries for anything the router depends on — logging, NTP, AAA — so they survive a DNS outage.ip dns server is a branch convenience, not a DNS server — fine for a handful of hosts, never a replacement for a real resolver.DNS is the quiet dependency behind logging, VPNs, and auth — when it breaks, everything looks broken. I design resolver and caching layouts across Cisco and MikroTik sites, with the failure modes engineered out. Let's make yours boring.
Book a Discovery Call →