cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
540
Views
0
Helpful
1
Replies

Reverse DNS requests from PAN 2.6

Antho_Balitrand
Level 1
Level 1

Hello Cisco Community ! 

 

I noticed that on my ISE 2.6 deployment, my PAN sends a huge amount of reverse DNS requests (PTR) for each and every incoming connection. 

I know that reverse DNS is used for each ISE deployment node or when using DNS probe on the PSNs (which is OK), but why is my PAN sending a PTR requests for each incoming connection from an admin user connecting to the PAN GUI ? 

(I mean like 2 requests per second...) 

 

Is it a normal behaviour ? Why is it needed ? Can we configure any cache somewhere to limit the amount of requests ? 

 

Thanks for your help ! 

 

 

Anthony

1 Reply 1

Arne Bier
VIP
VIP

excellent question - the only bit I know is that PTR records are required for some of the AD integration functionality. Why exactly? Not sure - but it's in the Admin/Install Guide somewhere.

 

Someone from the Cisco BU should be able to answer this.