Cisco Secure Access – Akamai Domain Access Issues

Monitoring

We have implemented a partial workaround for the currently identified affected domains. Customers should begin seeing restored access to these domains.

The underlying issue has not been fully resolved, and other Akamai-hosted domains may continue to return SERVFAIL responses. We are monitoring the effectiveness of this mitigation and continuing to work with Akamai toward a full resolution.

Customers who continue to experience issues can use the previously provided workaround to bypass affected domains from Cisco DNS. Additional updates will be provided as new information becomes available.
Posted Oct 02, 2026 - 23:02 UTC

Identified

We have identified that the issue occurs with domains hosted on Akamai IPv6 name servers that return a DNS response that is larger than 1410 bytes. These responses are being truncated which causes a Servfail response from the Cisco resolvers. We are continuing to work with Akamai to resolve this issue, we have the following proposed workaround.

Work Around
You can bypass the impacted domains from Cisco DNS. This can be performed with the Domain Management configuration for managed devices (Virtual Appliances and Roaming Clients) and with conditional forwarding rules on local DNS servers externally forwarding to Cisco DNS.
Posted Oct 02, 2026 - 22:23 UTC

Investigating

Customers using Cisco Secure Access might be unable to access some Akamai-hosted domains due to DNSSEC validation failure.Our teams are investigating and working to restore access. We will provide updates as more information becomes available.
Posted Oct 02, 2026 - 20:14 UTC
This incident affects: Global (DNS).