cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1453
Views
0
Helpful
2
Replies

tacacs-server dns-alias-lookup

cclem
Level 1
Level 1

All IOS commands entered in the switch take 18 seconds to process.  I noticed that the following command tacacs-server dns-alias-lookup was enabled.  Disabling this command allows the switch to process the IOS commands without any delay.

I can't find any detailed information regarding this use of this command. Can someone provide a real world business use as to when is it appropriate to enable this command?

2 Replies 2

Jatin Katyal
Cisco Employee
Cisco Employee

We use this command to enable IP Domain Name System (DNS) alias lookup for TACACS+ servers. Due to this it does reverse dns lookup. In scnarios where we don't have a dns server configured or defined, command cause a dns request to be generated  and it uses broadcast domain (255.255.255.255) and eventually timed out and adds lots of delay.

There are few tacacs+ related known issue with this command. Here is one of those.

CSCtc94806    tacacs-server dns-alias-lookup causes high CPU on TPLUS process

Jatin Katyal
- Do rate helpful posts -

~Jatin

minkumar
Level 1
Level 1

Hey

  its a  bug in IOS 15.1, in case if you are using IOS 15.1

Regards

Minakshi (Do rate the helpful posts)