RSAWeb down in my area

Big RSAWeb outage

Internet service provider (ISP) RSAWeb was hit by a major network outage on Wednesday, leaving its customers without Internet connectivity countrywide.

RSAWeb first posted a network notice at 06:51 AM on its Facebook and Twitter pages, informing customers that it was observing a service-impacting event on its cloud.
I heard you on the radio lol
 
As of 10 pm tonight wifi and ethernet were still not connecting on my laptop and PC, until I manually configured the DNS. I used the cloudfare one (1.1.1.1). Still not a great situation when so many users aren't likely to be aware or able to change these settings.

Anyway, would the more knowledgeable folks here recommend leaving DNS on this manual setting going forward, even if RSAweb sorts out all it issues? I think I heard somewhere that these other DNS servers can be faster than the ISP default?

On another weird note, my phone and chromecast were able to connect from early afternoon without any change to DNS settings (once my router light went from red to green). Not sure why it was different for them versus my PC and laptop.
 
As of 10 pm tonight wifi and ethernet were still not connecting on my laptop and PC, until I manually configured the DNS. I used the cloudfare one (1.1.1.1). Still not a great situation when so many users aren't likely to be aware or able to change these settings.

Anyway, would the more knowledgeable folks here recommend leaving DNS on this manual setting going forward, even if RSAweb sorts out all it issues? I think I heard somewhere that these other DNS servers can be faster than the ISP default?

On another weird note, my phone and chromecast were able to connect from early afternoon without any change to DNS settings (once my router light went from red to green). Not sure why it was different for them versus my PC and laptop.
For your first point, if you are outside of CPT (or WC), leave it on non-ISP DNS. If you are in JHB and somehow they are needing to send your DNS to CPT, its a bottleneck.
If you are in CPT, I'd go back once they sort out their issues.

ISP DNS is pretty important, because they can make changes or route you to the best resources via DNS if they need to, as an example, some ISPs use CDNs they host and only rely on ISP DNS to make that happen.
I recommend to everyone without a valid reason to change, to stay on ISP DNS.

Regarding your Chromecast, It has hard-coded DNS for Google. Found this out when working with a Pihole a while back, it will always go direct to Google no matter what your router is set to.

For your phone, it should usually stick to whatever your Wi-Fi is telling it to use, but, if you switched to mobile data (and thus, the DNS records were resolved) then went back to Wi-Fi shortly after, your phones DNS cache may have had the records already and didn't need any DNS at that moment, but thats just a guess.
 
For your first point, if you are outside of CPT (or WC), leave it on non-ISP DNS. If you are in JHB and somehow they are needing to send your DNS to CPT, its a bottleneck.
If you are in CPT, I'd go back once they sort out their issues.

ISP DNS is pretty important, because they can make changes or route you to the best resources via DNS if they need to, as an example, some ISPs use CDNs they host and only rely on ISP DNS to make that happen.
I recommend to everyone without a valid reason to change, to stay on ISP DNS.

Regarding your Chromecast, It has hard-coded DNS for Google. Found this out when working with a Pihole a while back, it will always go direct to Google no matter what your router is set to.

For your phone, it should usually stick to whatever your Wi-Fi is telling it to use, but, if you switched to mobile data (and thus, the DNS records were resolved) then went back to Wi-Fi shortly after, your phones DNS cache may have had the records already and didn't need any DNS at that moment, but thats just a guess.
Thanks this was very informative!
 
JHB is still major issues. Our warehouse is at a standstil because the Stupid scanners that they use you can not change the DNS on it.
 
Mine started working around 9pm last night. I see Maroela media is still down. They must be pissed, probably looking at moving somewhere else.
 
So I can confirm they have been hit by Ransomware, we have customers with hosted services there that we are currently working on migrating to MS Azure.
 
So I can confirm they have been hit by Ransomware, we have customers with hosted services there that we are currently working on migrating to MS Azure.
Explains the extended downtime, not the first time they have been compromised
 
So I can confirm they have been hit by Ransomware, we have customers with hosted services there that we are currently working on migrating to MS Azure.
I doubt ransomware? their virtual environment runs vmware as far as I am aware, and that runs esxi on the hosts. Even the VCS in vmware doesnt run windows any more.

I do however feel for the engineers who needs to get everything back up. shitty place to be in.
 
I doubt ransomware? their virtual environment runs vmware as far as I am aware, and that runs esxi on the hosts. Even the VCS in vmware doesnt run windows any more.

I do however feel for the engineers who needs to get everything back up. shitty place to be in.
Its still pretty possible, especially if they had the hosts exposed to the internet, or had an internal network breach. There is a wide list of threats that are VMWare Specific, targeting ESXI directly.

VMWare published them here, if you'd like some nightmares:


Once the threat actor have access to a host, and can target a datastore, some of them encrypt disks, etc.
 
Last edited:
Heard from our tech-contact there. Unofficially, he basically confirms its ransomware and I should consider my backup options but couldn't say more

From the little mentioned, it seems issue is storage related somehow
 
explains why the 2 "Engineers" I deal with there were very short off and would not give answers as do not think they want to say that it Ransonware. I feel for the guys as I know what preasure they are under
 
explains why the 2 "Engineers" I deal with there were very short off and would not give answers as do not think they want to say that it Ransonware. I feel for the guys as I know what preasure they are under
Also could explain why the official status updates from RSAWEB about what the problem is have been so vague
 
Top
Sign up to the MyBroadband newsletter
X