Back to blog

Cisco / IOS  ·  Fundamentals  ·  October 2026

Cisco IOS
DNS & Name Services

A Cisco router is a modest DNS citizen: a resolver for its own management traffic, a place for a few static host mappings, and — if you ask it — a small caching server for a branch. Knowing exactly how much it does (and the one setting that hangs your CLI for 30 seconds) keeps name resolution out of your troubleshooting. The MikroTik twin, with DoH and FQDN firewalling, is MikroTik: DNS, DoH & FQDN filtering.

Cisco IOS DNS Resolver Caching Fundamentals

DNS on IOS splits cleanly in two. Most of the time the router is a client — it resolves ntp.example.com, a TACACS hostname, or the name you typed at the CLI. Occasionally you make it a server: static ip host entries, or a lightweight caching resolver for a small site that has no dedicated DNS box.

The honest framing: a router is not a DNS server. ip dns server is fine for a handful of hosts at a branch; anything real belongs on BIND, Unbound, Pi-hole, or AD DNS. This post covers the resolver you always use, the static entries you'll actually need, the caching server where it makes sense, and the ip domain lookup behaviour that has cost everyone 30 seconds of staring at a frozen terminal.

Prerequisites
CLIENT asks for a name IOS ROUTER ip dns server cache + ip host UPSTREAM 8.8.8.8 / ISP query cache hit → answer, no upstream miss: recurse answer

01

The Resolver — And the Hang Everyone Hits

By default IOS tries to resolve any unrecognised word you type as a hostname — via broadcast. That's the frozen-terminal bug. Fix the resolver config and the CLI behaviour in the same breath.

IOS — resolver config done right
# Point the router at real resolvers and give it a default domain.
R1(config)# ip name-server 1.1.1.1 9.9.9.9
R1(config)# ip domain name lab.lan        # appended to unqualified names
R1(config)# ip domain lookup              # enable resolution (on by default)

# Pin lookups to a stable source so ACLs/logs see one IP (same
# discipline as AAA/syslog source-interface).
R1(config)# ip domain lookup source-interface Loopback0
⚠ Gotcha — Why Your CLI Freezes for 30 Seconds

Type a command wrong (say you fat-finger sh ip rote) and IOS decides the unknown word is a hostname. With no name-server set it broadcasts for it and the CLI blocks until the attempt times out — the classic "I can't type anything" freeze. Two cures: on boxes that don't need DNS, no ip domain lookup; on boxes that do, set line vty 0 4 / transport preferred none so a mistyped command isn't treated as a telnet target. If you're stuck mid-hang, Ctrl+Shift+6 aborts it.

02

Static Host Mappings

A few names you don't want to depend on DNS for — the syslog box, the NTP master, a jump host. ip host is the router's /etc/hosts and always wins over the resolver.

IOS — static A / AAAA entries
R1(config)# ip host syslog.lab.lan 10.0.0.5
R1(config)# ip host ntp.lab.lan 10.0.0.1
R1(config)# ip host v6host.lab.lan 2001:db8:10::5   # AAAA

# Now you can reference names in config and they survive a DNS outage.
R1(config)# logging host syslog.lab.lan
R1(config)# ntp server ntp.lab.lan
💡 Pro Tip — Static Entries for Anything Load-Bearing

Infrastructure the router depends on to function — its logging collector, NTP source, AAA server — should resolve even when DNS is down, because those are exactly the services you lean on during an outage. Pin them with ip host. Keep dynamic resolution for everything else.

03

IOS as a Small Caching DNS Server

At a branch with no DNS box, the router can answer clients directly: serve its static entries, cache recursive answers, and forward the rest upstream. Keep expectations small.

IOS — caching name server for a branch
# Turn the router into a DNS server. It answers 'ip host' entries,
# caches answers it recurses, and forwards misses to the name-servers.
R1(config)# ip dns server
R1(config)# ip name-server 1.1.1.1 9.9.9.9   # upstream for cache misses

# Hand this router's own LAN IP to clients as their DNS server via DHCP.
R1(config)# ip dhcp pool LAN
R1(dhcp-config)# network 10.10.10.0 255.255.255.0
R1(dhcp-config)# dns-server 10.10.10.1          # = this router
R1(dhcp-config)# domain-name lab.lan
⚠ Gotcha — Don't Make It an Open Resolver

If the router has a public interface and ip dns server is on, it will happily answer recursive queries from the internet — making you a free amplifier for DNS reflection DDoS and leaking internal names. Restrict UDP/TCP 53 to inside sources with an ACL on the WAN interface, the same way you'd lock down the MikroTik resolver. A branch router should answer its own clients, nobody else.

IOS — keep port 53 inside-only
R1(config)# ip access-list extended WAN-IN
R1(config-ext-nacl)# deny udp any any eq domain
R1(config-ext-nacl)# deny tcp any any eq domain
R1(config-ext-nacl)# permit ip any any       # (rest of your edge policy)
R1(config)# interface Gi0/0
R1(config-if)# ip access-group WAN-IN in

04

Verify & Troubleshoot Safe to Run

Prove resolution works, read the cache, and watch a live query. All read-only.

IOS — confirm name resolution end to end
R1# show hosts                     # static + cached entries, TTLs
R1# show ip dns view               # server/forwarder state
R1# ping ntp.lab.lan               # resolves, then pings
R1# show hosts summary
R1# debug domain                   # lab box only — watch queries live
R1# clear host *                   # flush the cache when testing
SymptomLikely cause
CLI freezes on a typoip domain lookup on + no name-server → fix per §01
Names resolve from router, not clientsDHCP dns-server points at the wrong IP, or ip dns server off
Resolution works, then stopsUpstream unreachable; cache expired — check ip name-server reachability
Internal names leak / abuse reportsOpen resolver — ACL port 53 inbound (§03)

Takeaways

  1. Always set ip name-server — and either disable ip domain lookup or set transport preferred none so typos don't freeze the CLI.
  2. Pin ip domain lookup source-interface to a loopback, the same discipline as AAA/syslog/NTP.
  3. Static ip host entries for anything the router depends on — logging, NTP, AAA — so they survive a DNS outage.
  4. ip dns server is a branch convenience, not a DNS server — fine for a handful of hosts, never a replacement for a real resolver.
  5. Never run it as an open resolver — ACL UDP/TCP 53 to inside sources on any public interface.

Name resolution that doesn't fall over?

DNS is the quiet dependency behind logging, VPNs, and auth — when it breaks, everything looks broken. I design resolver and caching layouts across Cisco and MikroTik sites, with the failure modes engineered out. Let's make yours boring.

Book a Discovery Call →