<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OpenDNS blocks https requests, but not http in OpenDNS</title>
    <link>https://community.cisco.com/t5/opendns/opendns-blocks-https-requests-but-not-http/m-p/5179695#M6407</link>
    <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Also, did you flush your caches?&amp;nbsp; &lt;A href="https://support.opendns.com/entries/26336865" rel="nofollow noreferrer"&gt;https://support.opendns.com/entries/26336865&lt;/A&gt; &lt;BR /&gt;Else you may be served out of these caches with outdated stuff.&lt;/P&gt;
&lt;P&gt;Still problems?&amp;nbsp; Post the complete plain text output of the following commands:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; nslookup whoami.akamai.net&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; &lt;SPAN class="s1"&gt;nslookup xvideos.com&lt;/SPAN&gt;&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Tue, 23 Feb 2016 09:41:53 GMT</pubDate>
    <dc:creator>rotblitz</dc:creator>
    <dc:date>2016-02-23T09:41:53Z</dc:date>
    <item>
      <title>OpenDNS blocks https requests, but not http</title>
      <link>https://community.cisco.com/t5/opendns/opendns-blocks-https-requests-but-not-http/m-p/5179689#M6401</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;I'm facing a weird problem with OpenDNS. It blocks successfully https requests to, say, xvideos.com; the browser complains about the certificate and doesn't let me go through, which is fine with me. But If I try to open &lt;A href="http://xvideos.com" rel="nofollow noreferrer"&gt;http://xvideos.com&lt;/A&gt;, the request goes through normally.&lt;BR /&gt;&lt;BR /&gt;My network has its own DNS server that points to OpenDNS. And it resolves xvideos IP as expected:&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;$ nslookup xvideos.com&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Server:&lt;SPAN class="s1"&gt; &lt;/SPAN&gt;&lt;SPAN class="s1"&gt; &lt;/SPAN&gt;192.168.0.3&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;Address:&lt;/SPAN&gt;&lt;SPAN class="s1"&gt; &lt;/SPAN&gt;&lt;SPAN class="s1"&gt;192.168.0.3#53&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Non-authoritative answer:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Name:&lt;SPAN class="s1"&gt; &lt;/SPAN&gt;xvideos.com&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Address: 146.112.61.106&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;What am I missing? Thanks!&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 22 Feb 2016 13:20:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/opendns-blocks-https-requests-but-not-http/m-p/5179689#M6401</guid>
      <dc:creator>drickcanada</dc:creator>
      <dc:date>2016-02-22T13:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: OpenDNS blocks https requests, but not http</title>
      <link>https://community.cisco.com/t5/opendns/opendns-blocks-https-requests-but-not-http/m-p/5179690#M6402</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;I do not see any evidence that you're using OpenDNS at all.&amp;nbsp; I rather doubt it.&amp;nbsp; It's the browser complaining, not OpenDNS, and you didn't say you got an OpenDNS block page.&amp;nbsp; What does &lt;A href="http://welcome.opendns.com/" rel="nofollow noreferrer"&gt;http://welcome.opendns.com/&lt;/A&gt; come up with?&lt;/P&gt;
&lt;P&gt;You may also post the complete plain text output of the following diagnostic command:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; nslookup -type=txt debug.opendns.com&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 22 Feb 2016 13:43:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/opendns-blocks-https-requests-but-not-http/m-p/5179690#M6402</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2016-02-22T13:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: OpenDNS blocks https requests, but not http</title>
      <link>https://community.cisco.com/t5/opendns/opendns-blocks-https-requests-but-not-http/m-p/5179691#M6403</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Thanks for the response. Although I'm pretty sure I'm using OpenDNS, I'm no DNS expert.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://welcome.opendns.com" rel="nofollow noreferrer"&gt;http://welcome.opendns.com&lt;/A&gt; comes up with the expected OpenDNS message:&lt;BR /&gt;&lt;BR /&gt;Welcome to OpenDNS!&lt;/P&gt;
&lt;P&gt;Your Internet is safer, faster, and smarter&lt;BR /&gt;because you’re using OpenDNS.&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;Here's the output of nslookup:&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;$ nslookup -type=txt debug.opendns.com.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Server:&lt;SPAN class="Apple-tab-span"&gt; &lt;/SPAN&gt;&lt;SPAN class="Apple-tab-span"&gt; &lt;/SPAN&gt;192.168.0.3&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Address:&lt;SPAN class="Apple-tab-span"&gt; &lt;/SPAN&gt;192.168.0.3#53&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Non-authoritative answer:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;debug.opendns.com&lt;SPAN class="Apple-tab-span"&gt; &lt;/SPAN&gt;text = "server 1.mia"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;debug.opendns.com&lt;SPAN class="Apple-tab-span"&gt; &lt;/SPAN&gt;text = "flags 20 0 50 19500027F0071189EF3"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;debug.opendns.com&lt;SPAN class="Apple-tab-span"&gt; &lt;/SPAN&gt;text = "originid 42187080"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;debug.opendns.com&lt;SPAN class="Apple-tab-span"&gt; &lt;/SPAN&gt;text = "actype 2"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;debug.opendns.com&lt;SPAN class="Apple-tab-span"&gt; &lt;/SPAN&gt;text = "bundle 8450146"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;debug.opendns.com&lt;SPAN class="Apple-tab-span"&gt; &lt;/SPAN&gt;text = "source 131.255.81.24:63564"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Authoritative answers can be found from:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 22 Feb 2016 17:57:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/opendns-blocks-https-requests-but-not-http/m-p/5179691#M6403</guid>
      <dc:creator>drickcanada</dc:creator>
      <dc:date>2016-02-22T17:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: OpenDNS blocks https requests, but not http</title>
      <link>https://community.cisco.com/t5/opendns/opendns-blocks-https-requests-but-not-http/m-p/5179692#M6404</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;This looks promising.&amp;nbsp; Ensure that your IP address &lt;SPAN class="s1"&gt;131.255.81.24&lt;/SPAN&gt; is registered at &lt;A href="https://dashboard.opendns.com/settings/" rel="nofollow noreferrer"&gt;https://dashboard.opendns.com/settings/&lt;/A&gt; - i.e. that &lt;SPAN class="s1"&gt;42187080&lt;/SPAN&gt; is your network ID and not another user's, else you would use the other user's settings.&lt;/P&gt;
&lt;P&gt;Did you flush your caches?&amp;nbsp; &lt;A href="https://support.opendns.com/entries/26336865" rel="nofollow noreferrer"&gt;https://support.opendns.com/entries/26336865&lt;/A&gt; &lt;BR /&gt;Else you may be served out of these caches with outdated stuff.&lt;/P&gt;
&lt;P&gt;Still problems?&amp;nbsp; Post the complete plain text output of the following commands:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; nslookup whoami.akamai.net&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; &lt;SPAN class="s1"&gt;nslookup &lt;A href="http://www.xvideos.com" rel="nofollow noreferrer"&gt;www.xvideos.com&lt;/A&gt;&lt;/SPAN&gt;&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 23 Feb 2016 09:38:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/opendns-blocks-https-requests-but-not-http/m-p/5179692#M6404</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2016-02-23T09:38:29Z</dc:date>
    </item>
    <item>
      <title>Re: OpenDNS blocks https requests, but not http</title>
      <link>https://community.cisco.com/t5/opendns/opendns-blocks-https-requests-but-not-http/m-p/5179693#M6405</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;This looks promising.&amp;nbsp; Ensure that your IP address &lt;SPAN class="s1"&gt;131.255.81.24&lt;/SPAN&gt; is registered at &lt;A href="https://dashboard.opendns.com/settings/" rel="nofollow noreferrer"&gt;https://dashboard.opendns.com/settings/&lt;/A&gt; - i.e. that &lt;SPAN class="s1"&gt;42187080&lt;/SPAN&gt; is your network ID and not another user's, else you would use the other user's settings.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 23 Feb 2016 09:39:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/opendns-blocks-https-requests-but-not-http/m-p/5179693#M6405</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2016-02-23T09:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: OpenDNS blocks https requests, but not http</title>
      <link>https://community.cisco.com/t5/opendns/opendns-blocks-https-requests-but-not-http/m-p/5179694#M6406</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Did you flush your caches?&amp;nbsp; &lt;A href="https://support.opendns.com/entries/26336865" rel="nofollow noreferrer"&gt;https://support.opendns.com/entries/26336865&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Else you may be served out of these caches with outdated stuff.&lt;/P&gt;
&lt;P&gt;Still problems?&amp;nbsp; Post the complete plain text output of the following commands:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; nslookup whoami.akamai.net&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; &lt;SPAN class="s1"&gt;nslookup &lt;A href="http://www.xvideos.com" rel="nofollow noreferrer"&gt;www.xvideos.com&lt;/A&gt;&lt;/SPAN&gt;&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 23 Feb 2016 09:39:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/opendns-blocks-https-requests-but-not-http/m-p/5179694#M6406</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2016-02-23T09:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: OpenDNS blocks https requests, but not http</title>
      <link>https://community.cisco.com/t5/opendns/opendns-blocks-https-requests-but-not-http/m-p/5179695#M6407</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Also, did you flush your caches?&amp;nbsp; &lt;A href="https://support.opendns.com/entries/26336865" rel="nofollow noreferrer"&gt;https://support.opendns.com/entries/26336865&lt;/A&gt; &lt;BR /&gt;Else you may be served out of these caches with outdated stuff.&lt;/P&gt;
&lt;P&gt;Still problems?&amp;nbsp; Post the complete plain text output of the following commands:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; nslookup whoami.akamai.net&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; &lt;SPAN class="s1"&gt;nslookup xvideos.com&lt;/SPAN&gt;&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 23 Feb 2016 09:41:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/opendns-blocks-https-requests-but-not-http/m-p/5179695#M6407</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2016-02-23T09:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: OpenDNS blocks https requests, but not http</title>
      <link>https://community.cisco.com/t5/opendns/opendns-blocks-https-requests-but-not-http/m-p/5179696#M6408</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Yes, those are my IP address and network ID. I tried flushing the DNS cache. I also tried getting rid of my local DNS and pointed my machine's DNS directly to OpenDNS. This is really weird. It looks like I'm resolving the expected IP for xvideos (146.112.61.106 is an OpenDNS IP), but my computer still fetches the contents from said website. The only other thing I can think of is that my ISP is caching requests and serving me whatever they have cached for xvideos. That would explain why https gets blocked properly as it doesn't get cached. I will get in touch with them to see if that's a possibility.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P class="p1"&gt;$ sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;$ nslookup whoami.akamai.net&lt;/P&gt;
&lt;P class="p1"&gt;Server: 192.168.0.3&lt;/P&gt;
&lt;P class="p1"&gt;Address: 192.168.0.3#53&lt;/P&gt;
&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;Non-authoritative answer:&lt;/P&gt;
&lt;P class="p1"&gt;Name: whoami.akamai.net&lt;/P&gt;
&lt;P class="p1"&gt;Address: 204.194.239.17&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;$ nslookup xvideos.com&lt;/P&gt;
&lt;P class="p1"&gt;Server: 192.168.0.3&lt;/P&gt;
&lt;P class="p1"&gt;Address: 192.168.0.3#53&lt;/P&gt;
&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;Non-authoritative answer:&lt;/P&gt;
&lt;P class="p1"&gt;Name: xvideos.com&lt;/P&gt;
&lt;P class="p1"&gt;Address: 146.112.61.106&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;Just so no browser cache would throw me off, I tried to fetch xvideos with curl and it worked normally:&lt;/P&gt;
&lt;P class="p1"&gt;$ curl -v xvideos.com&lt;/P&gt;
&lt;P class="p1"&gt;* Rebuilt URL to: xvideos.com/&lt;/P&gt;
&lt;P class="p1"&gt;* &amp;nbsp; Trying 146.112.61.106...&lt;/P&gt;
&lt;P class="p1"&gt;* Connected to xvideos.com (146.112.61.106) port 80 (#0)&lt;/P&gt;
&lt;P class="p1"&gt;&amp;gt; GET / HTTP/1.1&lt;/P&gt;
&lt;P class="p1"&gt;&amp;gt; Host: xvideos.com&lt;/P&gt;
&lt;P class="p1"&gt;&amp;gt; User-Agent: curl/7.43.0&lt;/P&gt;
&lt;P class="p1"&gt;&amp;gt; Accept: */*&lt;/P&gt;
&lt;P class="p1"&gt;&amp;gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;* HTTP 1.0, assume close after body&lt;/P&gt;
&lt;P class="p1"&gt;&amp;lt; HTTP/1.0 301 Moved Permanently&lt;/P&gt;
&lt;P class="p1"&gt;&amp;lt; Server: nginx&lt;/P&gt;
&lt;P class="p1"&gt;&amp;lt; Date: Tue, 23 Feb 2016 12:04:22 GMT&lt;/P&gt;
&lt;P class="p1"&gt;&amp;lt; Content-Type: text/html; charset=iso-8859-1&lt;/P&gt;
&lt;P class="p1"&gt;&amp;lt; Location: &lt;A href="http://www.xvideos.com/" rel="nofollow noreferrer"&gt;http://www.xvideos.com/&lt;/A&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;lt; Content-Length: 231&lt;/P&gt;
&lt;P class="p1"&gt;&amp;lt; Connection: close&lt;/P&gt;
&lt;P class="p1"&gt;&amp;lt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;lt;!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"&amp;gt;&lt;/P&gt;
&lt;P class="p1"&gt;...&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 23 Feb 2016 12:14:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/opendns-blocks-https-requests-but-not-http/m-p/5179696#M6408</guid>
      <dc:creator>drickcanada</dc:creator>
      <dc:date>2016-02-23T12:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: OpenDNS blocks https requests, but not http</title>
      <link>https://community.cisco.com/t5/opendns/opendns-blocks-https-requests-but-not-http/m-p/5179697#M6409</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Yes, this&amp;nbsp;204.194.239.17 is related to OpenDNS' Miami location: Miami, US &amp;nbsp;&amp;nbsp; &amp;nbsp;NAP of the Americas &amp;nbsp;&amp;nbsp; &amp;nbsp;NAP of the Americas &amp;nbsp;&amp;nbsp; &amp;nbsp;204.194.239.0/24 &lt;BR /&gt;as of &lt;A href="https://www.opendns.com/data-center-locations/" rel="nofollow noreferrer"&gt;https://www.opendns.com/data-center-locations/&lt;/A&gt; &lt;BR /&gt;And&amp;nbsp;146.112.61.106 is hit-adult.opendns.com indicating that the domain is blocked by category.&amp;nbsp; So, all is fine from a DNS perspective.&lt;/P&gt;
&lt;P&gt;And also cURL resolves to hit-adult.opendns.com.&amp;nbsp; But surprisingly it HTTP GETs their real data which is a HTTP 301 webhop to &lt;A href="http://www.xvideos.com/" rel="nofollow noreferrer"&gt;http://www.xvideos.com/&lt;/A&gt; indicating that this must be cached somewhere, as you correctly said.&lt;/P&gt;
&lt;P&gt;Perform this cache check to see if there's stealthed transparent proxy caching by your ISP: &lt;A href="http://www.lagado.com/tools/cache-test" rel="nofollow noreferrer"&gt;http://www.lagado.com/tools/cache-test&lt;/A&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 23 Feb 2016 14:01:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/opendns-blocks-https-requests-but-not-http/m-p/5179697#M6409</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2016-02-23T14:01:57Z</dc:date>
    </item>
  </channel>
</rss>

