cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
268
Views
0
Helpful
9
Replies

Open DNS blocking more than it should?

jemlay
Level 1
Level 1

My filtering level is set to NONE.  I simply block 3 domains.  Adobe.com, spotify.com and doubleclick.net.

That's all I need it for at the moment.  However I noticed that two specific apps don't work on my iOS devices.  ESPN and Disney XD.  They get to their loading screen and simply load forever.  I also noticed that this site doesn't work:

http://watchdisneyxd.go.com/live

If I change my DNS to 8.8.8.8, everything goes back to working fine.  Put OpenDNS back and that site and those apps stop working again.  So that's pretty much singles out OpenDNS.

Why is OpenDNS blocking these sites?

 

EDIT:

Add siriusxm.com to the list.  I always wondered why that site never worked.  OpenDNS is blocking that at well.

Removing doubleclick and spotify didn't help.

9 Replies 9

sudipr
Level 1
Level 1

Yeah for FamilyShield it is blocking webmail too

rotblitz
Level 6
Level 6

"If I change my DNS to 8.8.8.8, everything goes back to working fine.  Put OpenDNS back and that site and those apps stop working again.  So that's pretty much singles out OpenDNS."

Certainly.  Google doesn't have any content filtering or blocking at all, but OpenDNS does according to your individual settings.

"Why is OpenDNS blocking these sites?"

Because you configured your OpenDNS settings to block these sites.  OpenDNS doesn't block them by default.

These sites load content from many domains, especially also CDN domains.  I do not believe you have blocked only adobe.com, spotify.com and doubleclick.net in your "always block" list.

Visit your blocked domains stats to see what domains are still blocked but maybe needed to access content. 
https://dashboard.opendns.com/stats/all/blockeddomains

"Yeah for FamilyShield it is blocking webmail too"

Oops, if you want to block only adobe.com, spotify.com and doubleclick.net, then you must not use the FamilyShield resolver addresses, but you must use the normal OpenDNS resolver addresses.  FamilyShield blocks a whole bunch of categories, not matter what you configure.

Also, you didn't mention that you flushed your caches after each settings change.  You must! 
https://support.opendns.com/entries/26336865-Clearing-the-DNS-Cache-on-Computers-Servers-and-Web-Browsers

Still having problems?  Post the complete plain text output of the following diagnostic commands here:

nslookup -type=txt debug.opendns.com
nslookup watchdisneyxd.go.com
nslookup www.siriusxm.com. 
nslookup www.espn.com.

jemlay
Level 1
Level 1

"Because you configured your OpenDNS settings to block these sites."

No, I didn't.  As I stated my filter is set to NONE.  I only added those domains to always block.  Also, as I stated I removed two of them and now only adobe.com is listed.  Here:

http://www.tec-systems.com/external/opendns.png

"Oops, if you want to block only adobe.com, spotify.com and doubleclick.net...."

That was someone else.

"Also, you didn't mention that you flushed your caches after each settings change.  You must!"

Yes, I clear my cache after waiting 30 minutes after changes.

 

Debug command:

Server:  ad1.xxxxxx.com
Address:  10.10.10.204

Non-authoritative answer:
debug.opendns.com       text =

        "server 3.pao"
debug.opendns.com       text =

        "flags 20 0 2F6 0"
debug.opendns.com       text =

        "originid 16102601"
debug.opendns.com       text =

        "actype 2"
debug.opendns.com       text =

        "bundle 4926781"
debug.opendns.com       text =

        "source 74.x.x.x:21999"

 

Picking one (disney):

Server:  ad1.xxxxx.com
Address:  10.10.10.204

Non-authoritative answer:
Name:    dxd-prod-site-1042970201.us-east-1.elb.amazonaws.com
Addresses:  107.20.175.27
          107.21.127.206
Aliases:  watchdisneyxd.go.com
          dxd-prod-site.aws.seabc.go.com

rotblitz
Level 6
Level 6

Good, but this watchdisneyxd.go.com (real name: dxd-prod-site-1042970201.us-east-1.elb.amazonaws.com, alias: dxd-prod-site.aws.seabc.go.com) is clearly not blocked by OpenDNS, but the real IP addresses 107.20.175.27 and 107.21.127.206 are returned.  If it still looks like being blocked, it must be something else, not OpenDNS.  Can you post a screen shot of the block page you're seeing?  (You can attach it here too.)

Your IP address 74.x.x.x is registered with OpenDNS network ID 16102601.  You should find this number in the URL when you're at your dashboard settings for this network.

jemlay
Level 1
Level 1

This kept popping up in the blacklist:

fpdownload2.macromedia.com

Clearly Macromedia is owned by Adobe but I DO NOT have that domain listed in my blocked domains.  Yet it's getting blocked anyway.  I highly suspect the Disney site and those apps are requiring information from that domain and are failing to run when it can't access them.

So right back to my original question....Open DNS blocking more than it should?  Why is it blocking macromedia.com?

Adding macromedia.com to my allow list didn't help.

 

So in a round about way, blocking adobe.com is causing various video streaming sites and apps to not function. 

rotblitz
Level 6
Level 6

"fpdownload2.macromedia.com"
"but I DO NOT have that domain listed in my blocked domains."

Ha, this is what you thinkg!  You do have it in your block list! 

nslookup fpdownload2.macromedia.com.
Server: dns1.local.prv
Address: 10.165.161.12

Non-authoritative answer:
Name:    a1293.d.akamai.net
Addresses: 95.101.0.83
                 95.101.0.88
Aliases: fpdownload2.macromedia.com
                fpdownload2.wip4.adobe.com
                fpdownload.macromedia.com.edgesuite.net

 
See that one of the aliases is fpdownload2.wip4.adobe.com ?  Therefore you have it blocked with your settings!  For sure, OpenDNS also blocks the aliases, else users would easily circumvent OpenDNS by using them.

jemlay
Level 1
Level 1

You know, I'm starting to get pissed off by your attitude.  So far you've done absolutely nothing to help other then tell me everything is my fault/problem and that I've done things that I've not done.

***I*** did NOT have it blocked.  OpenDNS is then blocking aliases which means they are blocking MORE than expected.  Exactly what I hinted to with my original question.  So then in fact blocking a domain could result in blocking many other domains.  That's not exactly on the surface of the UI for anyone to know especially when you're asked if you want to turn on additional filtering for that domain or ONLY THAT DOMAIN.

Even still someone should be able to block adobe then ALLOW specific aliases which isn't working.

alexahar
Cisco Employee
Cisco Employee

One area that is often confusing is when CNAME records are involved. A large percent of CNAME records are for content delivery networks which are globally whitelisted because they do not stand on their own; but in this case we've come across a few which were blocked. 

To allow the adobe/macromedia download sites, add the wip4.adobe.com domain to the whitelist which will allow the download without unblocking other content. I'd always recommend checking our domain tagging site (http://community.opendns.com/domaintagging/) for information regarding which CNAME records inherit properties from other domains which may cause such blocking. For example, fpdownload2.macromedia.com's page will show that there is an adobe.com CNAME which may cause an unexpected block due to a CNAME record (https://domain.opendns.com/fpdownload2.macromedia.com). Since the CNAME record also includes the target in its DNS lookup, therefore it is also captured in the DNS process and would cause a block if the target record from the CNAME were blocked. 

Since this is tricky, the stats for your network for blocked domains is a great place to start - and checking these domains at the domain tagging site is a great place to locate what CNAME record may be causing the issue. 

jemlay
Level 1
Level 1

Excellent, thank you Alexander!

I'll play with wip4.adobe.com.  Hopefully that's not responsible for Adobe app updates as that's why it's blocked in the first place.  None of our users are able to install applications yet all the adobe apps love to tell my users an update is available.  So they download and execute only to be told they can't.  Enter a ton of support tickets.  We've been happy with the block so far but noticed all these oddball apps and sites not working.  I wanted to get to the bottom of it before I ran into something else we couldn't do.