<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic site not blocking when it should be in OpenDNS</title>
    <link>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173937#M649</link>
    <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;&lt;A href="http://www.xhamster.com" rel="nofollow noreferrer"&gt;www.xhamster.com&lt;/A&gt; is being blocked as expected but for some reason m.xhamster.com works ?!&lt;/P&gt;
&lt;P&gt;I checked and m.xhamster.com is setup in opendns to inherit the tags from xhamster.com and therefore should be blocked.&lt;/P&gt;
&lt;P&gt;Have I missed something ?&lt;/P&gt;
&lt;P&gt;It looks like my config is correct since other sites look to be getting blocked fine.&lt;/P&gt;
&lt;P&gt;I'm on a static IP, using PFSense firewall in front of everyone and blocking port 53 requests that aren't directed at the PFSense interface (ie, if someone is trying to use another DNS server then PFSense will block it).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Wed, 17 Sep 2014 11:39:03 GMT</pubDate>
    <dc:creator>methom90wh</dc:creator>
    <dc:date>2014-09-17T11:39:03Z</dc:date>
    <item>
      <title>site not blocking when it should be</title>
      <link>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173937#M649</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;&lt;A href="http://www.xhamster.com" rel="nofollow noreferrer"&gt;www.xhamster.com&lt;/A&gt; is being blocked as expected but for some reason m.xhamster.com works ?!&lt;/P&gt;
&lt;P&gt;I checked and m.xhamster.com is setup in opendns to inherit the tags from xhamster.com and therefore should be blocked.&lt;/P&gt;
&lt;P&gt;Have I missed something ?&lt;/P&gt;
&lt;P&gt;It looks like my config is correct since other sites look to be getting blocked fine.&lt;/P&gt;
&lt;P&gt;I'm on a static IP, using PFSense firewall in front of everyone and blocking port 53 requests that aren't directed at the PFSense interface (ie, if someone is trying to use another DNS server then PFSense will block it).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 17 Sep 2014 11:39:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173937#M649</guid>
      <dc:creator>methom90wh</dc:creator>
      <dc:date>2014-09-17T11:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: site not blocking when it should be</title>
      <link>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173938#M650</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Further to this if I just go to xhamster.com (without the www) then I also proceed unblocked.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 17 Sep 2014 11:55:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173938#M650</guid>
      <dc:creator>methom90wh</dc:creator>
      <dc:date>2014-09-17T11:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: site not blocking when it should be</title>
      <link>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173939#M651</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;How did you block this site, via category or by individually blocking? &amp;nbsp;If the latter, and you have&amp;nbsp;&lt;A href="http://www.xhamster.com/" rel="nofollow noreferrer"&gt;www.xhamster.com&lt;/A&gt;&amp;nbsp;in your "always block" list, it will not block&amp;nbsp;m.xhamster.com, of course. &amp;nbsp;You had to have&amp;nbsp;xhamster.com in your blacklist to make it work for all subdomains, not just &lt;A href="http://www" rel="nofollow noreferrer"&gt;www&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Also, did you flush your caches after settings changes? &amp;nbsp;Or do you use IPv6 connectivity over the internet?&lt;/P&gt;
&lt;P&gt;If it isn't any of those, then post the complete plain text output of the following diagnostic commands here:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;nslookup -type=txt debug.opendns.com&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp;nslookup &lt;A href="http://www.exampleadultsite.com" rel="nofollow noreferrer"&gt;www.exampleadultsite.com&lt;/A&gt;&lt;STRONG&gt;.&amp;nbsp;&lt;BR /&gt;&lt;/STRONG&gt;&amp;nbsp; &amp;nbsp;nslookup &lt;A href="http://www.xhamster.com" rel="nofollow noreferrer"&gt;www.xhamster.com&lt;/A&gt;&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&amp;nbsp; &amp;nbsp;nslookup&amp;nbsp;m.xhamster.com&lt;STRONG style="font-size: 1em; line-height: 1.45em;"&gt;.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;"&lt;EM&gt;I'm on a static IP, using PFSense firewall in front of everyone and blocking port 53 requests&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;This is all irrelevant for your issue. &amp;nbsp;Where do you have the OpenDNS resolver addresses configured? &amp;nbsp;Did you ensure to use OpenDNS resolver addresses only, not any others, or leaving DNS server fields empty?&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 17 Sep 2014 12:10:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173939#M651</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2014-09-17T12:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: site not blocking when it should be</title>
      <link>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173940#M652</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Thanks for yu response rotblitz.&lt;/P&gt;
&lt;P&gt;I tried adding xhamster.com and m.xhamster.com to my always block list but they are still coming through.&amp;nbsp; I did fluch the dns entries on the PC I was using and restarted the dnsmasq service in pfsense. The OpenDNS resolver addresses are stored in PFsense and are the only servers that are listed (the other 2 fields are empty).&lt;/P&gt;
&lt;P&gt;Here are the results from the nslookups:&lt;BR /&gt;&lt;BR /&gt;C:\Users\Matt&amp;gt;nslookup -type=txt debug.opendns.com&lt;BR /&gt;Server:&amp;nbsp; fw01.localdomain&lt;BR /&gt;Address:&amp;nbsp; 192.168.61.1&lt;BR /&gt;&lt;BR /&gt;Non-authoritative answer:&lt;BR /&gt;debug.opendns.com&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; text =&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "server 7.syd"&lt;BR /&gt;debug.opendns.com&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; text =&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "flags 20 0 2F6 D00FF00300814C3"&lt;BR /&gt;debug.opendns.com&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; text =&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "originid 18762691"&lt;BR /&gt;debug.opendns.com&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; text =&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "actype 2"&lt;BR /&gt;debug.opendns.com&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; text =&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "bundle 5491861"&lt;BR /&gt;debug.opendns.com&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; text =&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "source 222.154.235.3:59259"&lt;BR /&gt;&lt;BR /&gt;C:\Users\Matt&amp;gt;nslookup &lt;A href="http://www.playboy.com" rel="nofollow noreferrer"&gt;www.playboy.com&lt;/A&gt;&lt;BR /&gt;Server:&amp;nbsp; fw01.localdomain&lt;BR /&gt;Address:&amp;nbsp; 192.168.61.1&lt;BR /&gt;&lt;BR /&gt;Non-authoritative answer:&lt;BR /&gt;Name:&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="http://www.playboy.com" rel="nofollow noreferrer"&gt;www.playboy.com&lt;/A&gt;&lt;BR /&gt;Addresses:&amp;nbsp; 67.215.65.130&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 67.215.65.130&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;C:\Users\Matt&amp;gt;nslookup &lt;A href="http://www.xhamster.com" rel="nofollow noreferrer"&gt;www.xhamster.com&lt;/A&gt;&lt;BR /&gt;Server:&amp;nbsp; fw01.localdomain&lt;BR /&gt;Address:&amp;nbsp; 192.168.61.1&lt;BR /&gt;&lt;BR /&gt;Non-authoritative answer:&lt;BR /&gt;Name:&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="http://www.xhamster.com" rel="nofollow noreferrer"&gt;www.xhamster.com&lt;/A&gt;&lt;BR /&gt;Addresses:&amp;nbsp; 67.215.65.131&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 67.215.65.131&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;C:\Users\Matt&amp;gt;nslookup m.xhamster.com&lt;BR /&gt;Server:&amp;nbsp; fw01.localdomain&lt;BR /&gt;Address:&amp;nbsp; 192.168.61.1&lt;BR /&gt;&lt;BR /&gt;Non-authoritative answer:&lt;BR /&gt;Name:&amp;nbsp;&amp;nbsp;&amp;nbsp; m.xhamster.com&lt;BR /&gt;Addresses:&amp;nbsp; 67.215.65.131&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 67.215.65.131&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 17 Sep 2014 12:34:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173940#M652</guid>
      <dc:creator>methom90wh</dc:creator>
      <dc:date>2014-09-17T12:34:52Z</dc:date>
    </item>
    <item>
      <title>Re: site not blocking when it should be</title>
      <link>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173941#M653</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;You're using OpenDNS, data centre Sydney, and your IP address&amp;nbsp;222.154.235.3 is registered with OpenDNS network ID&amp;nbsp;18762691. &amp;nbsp;You have configured the OpenDNS resolver addresses on a device fw01.localdomain [192.168.61.1].&lt;/P&gt;
&lt;P&gt;"&lt;EM&gt;The OpenDNS resolver addresses are stored in PFsense and are the only servers that are listed (the other 2 fields are empty).&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;So fill these two other fields with 208.67.222.220 and 208.67.220.222. &amp;nbsp;Else you will be using OpenDNS randomly only.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;One of the commands was "nslookup&amp;nbsp;&lt;A href="http://www.exampleadultsite.com/" rel="nofollow noreferrer"&gt;www.exampleadultsite.com&lt;/A&gt;&lt;STRONG&gt;.&lt;/STRONG&gt;", but not "nslookup&amp;nbsp;&lt;A href="http://www.playboy.com/" rel="nofollow noreferrer"&gt;www.playboy.com&lt;/A&gt;". &amp;nbsp;The site &lt;A href="http://www.exampleadultsite.com" rel="nofollow noreferrer"&gt;www.exampleadultsite.com&lt;/A&gt; really exists and is owned by OpenDNS for testing purposes...&lt;/P&gt;
&lt;P&gt;Well, &lt;A href="http://www.playboy.com" rel="nofollow noreferrer"&gt;www.playboy.com&lt;/A&gt; is being blocked by category (returned IP 67.215.65.130&amp;nbsp;for hit-adult.opendns.com), whereas &lt;A href="http://www.xhamster.com" rel="nofollow noreferrer"&gt;www.xhamster.com&lt;/A&gt; and m.xhamster.com are being blocked individually (returned IP 67.215.65.131&amp;nbsp;for hit-block.opendns.com). &amp;nbsp;You can remove all xhamster entries from your "always block" list, because they would be blocked nevertheless by category.&lt;/P&gt;
&lt;P&gt;Are you still able to visit xhamster.com and m.xhamster.com?&lt;/P&gt;
&lt;P&gt;Does ping return the real IP addresses of these domains?&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;ping xhamster.com&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp;ping m.xhamster.com&lt;/P&gt;
&lt;P&gt;Then you didn't correctly flush both, your local resolver cache, also on PFSense, and your browser cache, or the browser being used does not use your system settings, but somehow circumvents OpenDNS. &amp;nbsp;What browser are you using?&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 17 Sep 2014 13:03:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173941#M653</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2014-09-17T13:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: site not blocking when it should be</title>
      <link>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173942#M654</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;I've added the two new DNS servers. no change.&lt;/P&gt;
&lt;P&gt;C:\Users\Matt&amp;gt;nslookup &lt;A href="http://www.exampleadultsite.com" rel="nofollow noreferrer"&gt;www.exampleadultsite.com&lt;/A&gt;&lt;BR /&gt;Server:&amp;nbsp; fw01.localdomain&lt;BR /&gt;Address:&amp;nbsp; 192.168.61.1&lt;BR /&gt;&lt;BR /&gt;Non-authoritative answer:&lt;BR /&gt;Name:&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="http://www.exampleadultsite.com" rel="nofollow noreferrer"&gt;www.exampleadultsite.com&lt;/A&gt;&lt;BR /&gt;Addresses:&amp;nbsp; 67.215.65.130&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 67.215.65.130&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The pings are below.&amp;nbsp; It's not a local caching issue because I can navigate to new pages and they load fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;C:\Users\Matt&amp;gt;ping &lt;A href="http://www.xhamster.com" rel="nofollow noreferrer"&gt;www.xhamster.com&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Pinging &lt;A href="http://www.xhamster.com" rel="nofollow noreferrer"&gt;www.xhamster.com&lt;/A&gt; [67.215.65.131] with 32 bytes of data:&lt;BR /&gt;Reply from 67.215.65.131: bytes=32 time=76ms TTL=54&lt;BR /&gt;Reply from 67.215.65.131: bytes=32 time=76ms TTL=54&lt;BR /&gt;Reply from 67.215.65.131: bytes=32 time=76ms TTL=54&lt;BR /&gt;Reply from 67.215.65.131: bytes=32 time=74ms TTL=54&lt;BR /&gt;&lt;BR /&gt;Ping statistics for 67.215.65.131:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),&lt;BR /&gt;Approximate round trip times in milli-seconds:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Minimum = 74ms, Maximum = 76ms, Average = 75ms&lt;BR /&gt;&lt;BR /&gt;C:\Users\Matt&amp;gt;ping m.xhamster.com&lt;BR /&gt;&lt;BR /&gt;Pinging m.xhamster.com [67.215.65.131] with 32 bytes of data:&lt;BR /&gt;Reply from 67.215.65.131: bytes=32 time=77ms TTL=54&lt;BR /&gt;Reply from 67.215.65.131: bytes=32 time=79ms TTL=54&lt;BR /&gt;Reply from 67.215.65.131: bytes=32 time=76ms TTL=54&lt;BR /&gt;Reply from 67.215.65.131: bytes=32 time=85ms TTL=54&lt;BR /&gt;&lt;BR /&gt;Ping statistics for 67.215.65.131:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),&lt;BR /&gt;Approximate round trip times in milli-seconds:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Minimum = 76ms, Maximum = 85ms, Average = 79ms&lt;BR /&gt;&lt;BR /&gt;C:\Users\Matt&amp;gt;ping &lt;A href="http://www.xhamster.com" rel="nofollow noreferrer"&gt;www.xhamster.com&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Pinging &lt;A href="http://www.xhamster.com" rel="nofollow noreferrer"&gt;www.xhamster.com&lt;/A&gt; [67.215.65.131] with 32 bytes of data:&lt;BR /&gt;Reply from 67.215.65.131: bytes=32 time=84ms TTL=54&lt;BR /&gt;Reply from 67.215.65.131: bytes=32 time=106ms TTL=54&lt;BR /&gt;Reply from 67.215.65.131: bytes=32 time=132ms TTL=54&lt;BR /&gt;Reply from 67.215.65.131: bytes=32 time=135ms TTL=54&lt;BR /&gt;&lt;BR /&gt;Ping statistics for 67.215.65.131:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),&lt;BR /&gt;Approximate round trip times in milli-seconds:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Minimum = 84ms, Maximum = 135ms, Average = 114ms&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I'm using firefox but I just tried chrome and get the same issue.&amp;nbsp; The users can't circumvent OpenDNS because there is no way to bypass PFSense and still connect to the internet.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 17 Sep 2014 13:39:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173942#M654</guid>
      <dc:creator>methom90wh</dc:creator>
      <dc:date>2014-09-17T13:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: site not blocking when it should be</title>
      <link>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173943#M655</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;From the sounds of the above, since xhamster.com appears to have been visited before the blocks were in place, the most likely culprit of the lack of blocking is cached non-blocked DNS entries and browser cache data.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We'd also recommend, as mentioned above, that if there are multiple DNS server addresses to fill each one with OpenDNS addresses: 208.67.220.220 and 208.67.222.222 are the main two, and 208.67.220.222 and 208.67.222.220 are two additional for a 3rd and 4th slot.&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 17 Sep 2014 13:46:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173943#M655</guid>
      <dc:creator>alexahar</dc:creator>
      <dc:date>2014-09-17T13:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: site not blocking when it should be</title>
      <link>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173944#M656</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Hi Alexander.&amp;nbsp; The category blocks for xhamster would of been in place when I first setup OpenDNS on my network months ago.&lt;/P&gt;
&lt;P&gt;I only noticed m.xhamster.com because I was looking at my sons phone browser history.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I added the domains to always block to see if that would help.&lt;/P&gt;
&lt;P&gt;I'm not sure why the xhamster domain is being so differcult.&amp;nbsp; I also added reddit.com and imgur.com to my always block list and after 3 mins they are blocking correctly.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 17 Sep 2014 13:52:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173944#M656</guid>
      <dc:creator>methom90wh</dc:creator>
      <dc:date>2014-09-17T13:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: site not blocking when it should be</title>
      <link>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173945#M657</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;From your outputs everything is perfect and blocking should take effect. &amp;nbsp;OpenDNS doesn't return the real IP addresses for these sites, but their own ones which would redirect to the block page. &amp;nbsp;There's nothing more OpenDNS could do for you.&lt;/P&gt;
&lt;P&gt;That said, if you can still visit these sites, then your browsers disregard the system&amp;nbsp;(computer and PFSense) settings. &amp;nbsp;Do you have a proxy configured in some way? &amp;nbsp;Or use browser-addons which use proxy technology? &amp;nbsp;Or do you use an internal proxy server or VPN technology? &amp;nbsp;These would be good reasons why your browsers circumvent your OpenDNS settings. &amp;nbsp;&lt;STRONG&gt;What message does &lt;A href="http://welcome.opendns.com/" rel="nofollow noreferrer"&gt;http://welcome.opendns.com/&lt;/A&gt; show up with?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;"&lt;EM&gt;blocking port 53 requests that aren't directed at the PFSense interface... &amp;nbsp;The users can't circumvent OpenDNS because there is no way to bypass PFSense and still connect to the internet.&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;This is what you think. &amp;nbsp;If there's some form of proxy or VPN in use, it is still possible to circumvent OpenDNS, despite your port 53 blocking.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 17 Sep 2014 13:56:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173945#M657</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2014-09-17T13:56:00Z</dc:date>
    </item>
    <item>
      <title>Re: site not blocking when it should be</title>
      <link>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173946#M658</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Hi.&amp;nbsp; There is no proxy or VPN in play.&amp;nbsp; A linux box which has been off for months shows the same issue.&amp;nbsp; Interestingly part of the m.xhamster.com page is being blocked by OpenDNS (syndication.exoclick.com).&lt;/P&gt;
&lt;P&gt;I agree that the nslookup and ping commands show that openDNS is being used and is returning the right information.&lt;/P&gt;
&lt;P&gt;I just can't figure out why this one site is not being blocked.&amp;nbsp; As I said imgur and reddit were added about an hour ago and they are being blocked with no issue on the same PC's.&amp;nbsp; I could understand it better if OpenDNS wasn't being used at all but it seems that for this one domain something is causing an issue for me.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 17 Sep 2014 14:20:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173946#M658</guid>
      <dc:creator>methom90wh</dc:creator>
      <dc:date>2014-09-17T14:20:23Z</dc:date>
    </item>
    <item>
      <title>Re: site not blocking when it should be</title>
      <link>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173947#M659</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Is there any chance that the phone visiting m.xhamster.com was visited over the cellular network which would have been an unfiltered request?&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 17 Sep 2014 14:23:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173947#M659</guid>
      <dc:creator>alexahar</dc:creator>
      <dc:date>2014-09-17T14:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: site not blocking when it should be</title>
      <link>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173948#M660</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;No data allowed over the cell network but it'spossible they got to m.xhamster.com from another wireless site (maybe a friends house) that hasn't blocked it.&lt;/P&gt;
&lt;P&gt;I still can't figure out why PC's that have never been there before are showing the same issue.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 17 Sep 2014 14:26:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173948#M660</guid>
      <dc:creator>methom90wh</dc:creator>
      <dc:date>2014-09-17T14:26:40Z</dc:date>
    </item>
    <item>
      <title>Re: site not blocking when it should be</title>
      <link>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173949#M661</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Based on your account, any requests that are making it to OpenDNS from your registered IP have been filtered. Somehow, some requests aren't making it through to OpenDNS, or aren't leaving your network from the IP address registered to your Dashboard. Based on the test in your earlier reply, that lookup did report that it was associated with your account.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A way to try and diagnose the issue is to run the following nslookup command across the computers that aren't working and see if any report a originid that is correct (&lt;A href="http://bfg.opendns.com/networks/network.php?network_id=18762691" rel="nofollow noreferrer"&gt;18762691&lt;/A&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&lt;SPAN&gt;nslookup -type=txt debug.opendns.com. An in-browser test is to visit &lt;A href="http://welcome.opendns.com" rel="nofollow noreferrer"&gt;http://welcome.opendns.com&lt;/A&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 17 Sep 2014 14:33:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173949#M661</guid>
      <dc:creator>alexahar</dc:creator>
      <dc:date>2014-09-17T14:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: site not blocking when it should be</title>
      <link>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173950#M662</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;The output from that nslookup shows the correct originID and the welcome page looks fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 17 Sep 2014 14:49:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173950#M662</guid>
      <dc:creator>methom90wh</dc:creator>
      <dc:date>2014-09-17T14:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: site not blocking when it should be</title>
      <link>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173951#M663</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;All these indications lead to the setup working correctly. Next time it's not working right, follow up with the results of a diagnostic test with the instructions from&amp;nbsp;&lt;A href="https://support.opendns.com/entries/21841580" rel="nofollow noreferrer"&gt;https://support.opendns.com/entries/21841580&lt;/A&gt; if nslookup -type=txt debug.opendns.com shows some incorrect information. The key to tracking down the issue would be to catch it when it isn't working.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd also confirm that the filtering is working in Incognito/Private browsing if the filtering isn't working in the browser. There is a chance a browser extension is being used to bypass OpenDNS like the near-VPN ZenMate. Incognito mode disables all addons so it can be used as a test.&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 17 Sep 2014 15:03:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173951#M663</guid>
      <dc:creator>alexahar</dc:creator>
      <dc:date>2014-09-17T15:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: site not blocking when it should be</title>
      <link>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173952#M664</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;See results at &lt;A href="https://opendnsupdate.appspot.com/d/6157300683243520" rel="nofollow noreferrer"&gt;https://opendnsupdate.appspot.com/d/6157300683243520&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;All the tests I've done so far have mostly been in private mode.&lt;/P&gt;
&lt;P&gt;I'm pretty confident of the browser setup.&amp;nbsp; This issue is happening on my own PC as well as a base install linux box.&lt;/P&gt;
&lt;P&gt;I also allowed all port 53 traffic on the LAN and logged it.&amp;nbsp; Everything on my PC is going to the PFSense interface and not a 3rd party server.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 17 Sep 2014 15:16:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173952#M664</guid>
      <dc:creator>methom90wh</dc:creator>
      <dc:date>2014-09-17T15:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: site not blocking when it should be</title>
      <link>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173953#M665</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Everything does appear to be configured correctly and m.xhamster.com is being blocked when using the default DNS servers. Direct access to OpenDNS (208.67.222.222) on port 53 is being blocked; however, a nslookup to a third party DNS provider Level3 (4.2.2.1) was able to complete successfully and return the IP for m.xhamster.com.&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;Results for: nslookup m.xhamster.com. 4.2.2.1
stdout:
Server:  a.resolvers.level3.net
Address:  4.2.2.1
Name:    m.xhamster.com
Addresses:  2a02:b48:4000:1::4248
	  2a02:b48:4000:1::4247
	  2a02:b48:4000:1::4246
	  2a02:b48:4000:1::4249
	  88.208.24.59
	  88.208.24.58
	  88.208.24.56
	  88.208.24.57
&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;This indicates that it may be possible to use a different DNS server manually configured on a device and that the firewall isn't blocking other DNS providers like its expected to. You did say you opened up port 53 - and you should see this allowed DNS request for m.xhamster.com resolving unblocked to 4.2.2.1.&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 17 Sep 2014 15:21:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173953#M665</guid>
      <dc:creator>alexahar</dc:creator>
      <dc:date>2014-09-17T15:21:33Z</dc:date>
    </item>
    <item>
      <title>Re: site not blocking when it should be</title>
      <link>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173954#M666</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;See results at &lt;A href="https://opendnsupdate.appspot.com/d/5981648734650368" rel="nofollow noreferrer"&gt;https://opendnsupdate.appspot.com/d/5981648734650368&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I did a second test.&amp;nbsp; Not sure why direct access to 208.67.222.222 would be blocked.&amp;nbsp; Maybe I opened 53 up after I started the test.&lt;/P&gt;
&lt;P&gt;Looking now the fw hasn't blocked any traffic.&lt;/P&gt;
&lt;P&gt;Once I have this sorted I'll lock down 53 again to prevent people from using a 3rd party DNS.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 17 Sep 2014 15:36:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173954#M666</guid>
      <dc:creator>methom90wh</dc:creator>
      <dc:date>2014-09-17T15:36:00Z</dc:date>
    </item>
    <item>
      <title>Re: site not blocking when it should be</title>
      <link>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173955#M667</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;I haven't got to the bottom of this yet but it is related to my ISP.&amp;nbsp; Via my normal ISP I have the problem but when I used my phone to provide internet to my laptop OpenDNS blocked all 3 sites as expected.&lt;/P&gt;
&lt;P&gt;I probably won't get a chance to fix this until November as I'm just about to go on holiday.&lt;/P&gt;
&lt;P&gt;Thanks for all the help!&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 19 Sep 2014 06:02:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173955#M667</guid>
      <dc:creator>methom90wh</dc:creator>
      <dc:date>2014-09-19T06:02:59Z</dc:date>
    </item>
    <item>
      <title>Re: site not blocking when it should be</title>
      <link>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173956#M668</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;"&lt;EM&gt;I haven't got to the bottom of this yet but it is related to my ISP.&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;There may be a mismatch between your IP address used to send DNS traffic and your IP address used to send HTTP traffic.&lt;/P&gt;
&lt;P&gt;Your DNS IP address: &amp;nbsp; &amp;nbsp;nslookup myip.opendns.com&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;BR /&gt;Your web IP address: &amp;nbsp; &amp;nbsp; &lt;A href="http://myip.dnsomatic.com/" rel="nofollow noreferrer"&gt;http://myip.dnsomatic.com/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Are those different?&lt;/P&gt;
&lt;P&gt;Or is your ISP using a proxy or cache or NAT?&amp;nbsp;&lt;BR /&gt;&lt;A href="http://www.lagado.com/proxy-test" rel="nofollow noreferrer"&gt;http://www.lagado.com/proxy-test&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;A href="http://www.lagado.com/tools/cache-test" rel="nofollow noreferrer"&gt;http://www.lagado.com/tools/cache-test&lt;/A&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 19 Sep 2014 12:50:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/site-not-blocking-when-it-should-be/m-p/5173956#M668</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2014-09-19T12:50:25Z</dc:date>
    </item>
  </channel>
</rss>

