{"id":271471,"date":"2022-08-11T01:36:48","date_gmt":"2022-08-10T23:36:48","guid":{"rendered":"https:\/\/www.borncity.com\/blog\/?p=271471"},"modified":"2022-08-11T08:38:48","modified_gmt":"2022-08-11T06:38:48","slug":"microsoft-365-ausfall-durch-merics-firewall-10-august-2022","status":"publish","type":"post","link":"https:\/\/borncity.com\/blog\/2022\/08\/11\/microsoft-365-ausfall-durch-merics-firewall-10-august-2022\/","title":{"rendered":"Microsoft 365-Ausfall durch Cisco Meraki-Firewall (10. August 2022)"},"content":{"rendered":"<p>Am 10. August 2022 kam es bei den Diensten von Microsoft 365 zu einem Ausfall, der speziell Nordamerika aber auch den EMEA-Raum betraf. Nutzer hatten Probleme mit Office 365, Outlook und weiteren Diensten. Es lag wohl an einem Update f\u00fcr die Cisco Meraki-Firewall, die von Microsoft verwendet wird.<\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg05.met.vgwort.de\/na\/351d34c33ee744b786a54d7cb02a1205\" alt=\"\" width=\"1\" height=\"1\" \/>Auf Twitter hat Microsoft Probleme mit seinem Cloud-Diensten eingestanden, wie nachfolgende <a href=\"https:\/\/twitter.com\/MSFT365Status\/status\/1557347239416176641\" target=\"_blank\" rel=\"noopener\">Tweets<\/a> zeigen. Bereits in der initialen Nachricht wurde best\u00e4tigt, dass der Netzwerkverkehr \u00fcber verschiedene Regionen blockiert war.<\/p>\n<p><a href=\"https:\/\/twitter.com\/MSFT365Status\/status\/1557347239416176641\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" src=\"https:\/\/i.imgur.com\/IpSGjtM.png\" \/><\/a><\/p>\n<p>Schnell war klar, dass das Ganze mit von Microsoft verwendeten Firewall-L\u00f6sungen zusammen h\u00e4ngt. Blog-Leser Markus wies mich per Mail auf <a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-365-outage-triggered-by-meraki-firewall-false-positive\/\" target=\"_blank\" rel=\"noopener\">diesen Beitrag<\/a> von Bleeping Computer hin (danke daf\u00fcr). Der Ausfall wurde von einem Fehlalarm in der eingesetzten Cisco Meraki-Firewall ausgel\u00f6st, der verhinderte, dass sich Benutzer mit Exchange Online, Microsoft Teams, Outlook-Desktopclients und OneDrive for Business verbinden konnten.<\/p>\n<p>Ein Mitarbeiter von Cisco hat das in <a href=\"https:\/\/community.meraki.com\/t5\/Meraki-Service-Notices\/RESOLVED-Microsoft-vulnerability-and-IPS-SNORT\/ba-p\/156649\" target=\"_blank\" rel=\"noopener\">diesem Forenbeitrag<\/a> angesprochen. Eine von Microsoft gemeldete Sicherheitsl\u00fccke CVE-2022-35748\u00a0 l\u00f6st die die SNORT-Regel 1-60381 aus, was zu Problemen mit der Kommunikation durch die Firewall f\u00fchrte.\u00a0Inzwischen hat Microsoft das Problem aber wohl behoben (siehe auch die Hinweise bei Bleeping Computer). Blog-Leser Andreas P. hat mir noch nachfolgende Ausz\u00fcge aus dem Statusbereich des Admin Centers zukommen lassen (danke daf\u00fcr).<\/p>\n<blockquote><p>Published Time: 10.08.2022 19:56:28<br \/>\nThe firewall partner is currently reviewing options to remediate impact.<br \/>\nThis quick update is designed to give the latest information on this issue.<br \/>\nPublished Time: 10.08.2022 19:02:39<br \/>\nTitle: Some users may be unable to connect to multiple Microsoft 365 services.<br \/>\nUser Impact: Users may be unable to connect to multiple Microsoft 365 services.<br \/>\nMore info: Impacted services include, but are not limited to:<br \/>\n&#8211; Outlook desktop client<br \/>\n&#8211; OneDrive for Business<br \/>\n&#8211; Microsoft Teams<br \/>\nAffected customers have reported that disabling firewall rules blocking TLS 1.2 is mitigating impact. Some firewall vendors have published guidance on disabling the impacting rules, and we recommend contacting your firewall vendor for further assistance.<br \/>\nCurrent status: We continue to work with the firewall partner to investigate a Snort rule which is contributing to impact. Our focus remains on mitigation and from user reports, disabling the specific firewall rule provides immediate relief. Additionally, we continue to investigate recent changes within the Microsoft-managed environment to rule out potential causes of impact.<br \/>\nScope of impact: At this time, impact appears to be specific to some users who are served through the affected infrastructure.<br \/>\nNext update by: Wednesday, August 10, 2022, at 6:30 PM UTC<br \/>\nPublished Time: 10.08.2022 18:41:46<br \/>\nWe're continuing to work with the firewall partner to investigate the issue. Additionally, we monitoring feedback from impacted organizations that disabling a specific firewall rule, which blocks TLS 1.2, is mitigating impact.<br \/>\nThis quick update is designed to give the latest information on this issue.<br \/>\nPublished Time: 10.08.2022 17:25:42<br \/>\nTitle: Some users may be unable to connect to multiple Microsoft 365 services.<br \/>\nUser Impact: Users may be unable to connect to multiple Microsoft 365 services.<br \/>\nMore info: Impacted services include, but are not limited to:<br \/>\n&#8211; Outlook desktop client<br \/>\n&#8211; OneDrive for Business<br \/>\n&#8211; Microsoft Teams<br \/>\nAffected customers have reported that disabling firewall rules blocking TLS 1.2 is mitigating impact.<br \/>\nCurrent status: We've identified an increase in errors related to TLS 1.0 and 1.1 across Microsoft 365 services. We've confirmed that there have not been any recent changes to the service feature which is blocking the traffic. We're continuing to engage with the firewall partners to assist our investigation into the potential blocking of legitimate traffic. Additionally, we're working with impacted users to gather client logs.<br \/>\nScope of impact: At this time, impact appears to be specific to some users who are served through the affected infrastructure.<br \/>\nNext update by: Wednesday, August 10, 2022, at 5:00 PM UTC<br \/>\nPublished Time: 10.08.2022 17:01:14<br \/>\nWe're directly working with some of the affected users to aid in our investigation while continuing to engage with our firewall partners. Analysis into Microsoft 365 client endpoints is ongoing.<br \/>\nThis quick update is designed to give the latest information on this issue.<br \/>\nPublished Time: 10.08.2022 16:28:30<br \/>\nWe're looking at recent changes made within the Microsoft-managed infrastructure and reviewing endpoints that are leveraging TLS 1.2. Additionally, we're contacting firewall partners to assist our investigation.<br \/>\nThis quick update is designed to give the latest information on this issue.<br \/>\nPublished Time: 10.08.2022 15:53:29<br \/>\nTitle: Some users may be unable to connect to multiple Microsoft 365 services.<br \/>\nUser Impact: Users may be unable to connect to multiple Microsoft 365 services.<br \/>\nMore info: Impacted services include, but are not limited to:<br \/>\n&#8211; Outlook desktop client<br \/>\n&#8211; OneDrive for Business<br \/>\n&#8211; Microsoft Teams<br \/>\nCurrent status: After analyzing system telemetry and Fiddler logs from impacted users, we suspect that third-party firewall devices are potentially blocking legitimate Microsoft traffic. Affected customers have reported that disabling firewall rules blocking TLS 1.2 is mitigating impact. We're continuing our investigation into the underlying cause.<br \/>\nScope of impact: At this time, impact appears to be specific to some users who are served through the affected infrastructure.<br \/>\nNext update by: Wednesday, August 10, 2022, at 3:30 PM UTC<br \/>\nPublished Time: 10.08.2022 15:25:09<br \/>\nSome customers are able to mitigate impact by disabling a firewall rule that is blocking TLS 1.2.<br \/>\nThis quick update is designed to give the latest information on this issue.<br \/>\nPublished Time: 10.08.2022 14:57:17<br \/>\nWe're reviewing Exchange trace logs (ETL) from users who are experiencing impact. We believe the issue may be related to Active Directory (AD) services and are investigating this further.<br \/>\nThis quick update is designed to give the latest information on this issue.<br \/>\nPublished Time: 10.08.2022 14:41:52<br \/>\nTitle: Some users may be unable to connect to multiple Microsoft 365 services.<br \/>\nUser Impact: Users may be unable to connect to multiple Microsoft 365 services.<br \/>\nMore info: Impacted services include, but are not limited to:<br \/>\n&#8211; Outlook desktop client<br \/>\n&#8211; OneDrive for Business<br \/>\n&#8211; Microsoft Teams<br \/>\nCurrent status: We're reviewing system telemetry to isolate the source of the issue. Additionally, we're working with impacted users to gather network trace logs to assist our investigation.<br \/>\nScope of impact: At this time, impact appears to be specific to some users who are served through the affected infrastructure.<br \/>\nNext update by: Wednesday, August 10, 2022, at 2:00 PM UTC<\/p><\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>Am 10. August 2022 kam es bei den Diensten von Microsoft 365 zu einem Ausfall, der speziell Nordamerika aber auch den EMEA-Raum betraf. Nutzer hatten Probleme mit Office 365, Outlook und weiteren Diensten. Es lag wohl an einem Update f\u00fcr &hellip; <a href=\"https:\/\/borncity.com\/blog\/2022\/08\/11\/microsoft-365-ausfall-durch-merics-firewall-10-august-2022\/\">Weiterlesen <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7263,7862],"tags":[1171,987],"class_list":["post-271471","post","type-post","status-publish","format-standard","hentry","category-cloud","category-stoerung","tag-cloud","tag-storung"],"_links":{"self":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/271471","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/comments?post=271471"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/271471\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/media?parent=271471"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/categories?post=271471"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/tags?post=271471"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}