We've been seeing intermittent DNS failures specifically for Azure-hosted services (core windows.net, storage, etc.) over the last two weeks. Umbrella resolvers return SERVFAIL. Bypassing Umbrella works immediately.
Cisco support blames Azure. Azure support blames our DNS resolver. The usual "it's the other vendor" standoff.
Anyone else caught in this particular crossfire? I'm skeptical of the "everything is fine" posture from both sides when the failure pattern is so specific.
—EB
Yeah, that specific standoff is so frustrating. We had something similar with a different DNS security vendor and Azure about six months back.
It got resolved only after we escalated and provided packet captures showing the SERVFAIL coming from the resolver. Even then, both sides insisted their logs showed no issue.
Do you happen to know if the failures are coming from a specific Umbrella resolver IP, or is it across all of them? Might help narrow the "proof" you can give Cisco.