08-25-2014 10:55 AM
My filtering level is set to NONE. I simply block 3 domains. Adobe.com, spotify.com and doubleclick.net.
That's all I need it for at the moment. However I noticed that two specific apps don't work on my iOS devices. ESPN and Disney XD. They get to their loading screen and simply load forever. I also noticed that this site doesn't work:
http://watchdisneyxd.go.com/live
If I change my DNS to 8.8.8.8, everything goes back to working fine. Put OpenDNS back and that site and those apps stop working again. So that's pretty much singles out OpenDNS.
Why is OpenDNS blocking these sites?
EDIT:
Add siriusxm.com to the list. I always wondered why that site never worked. OpenDNS is blocking that at well.
Removing doubleclick and spotify didn't help.
08-25-2014 11:00 AM
Yeah for FamilyShield it is blocking webmail too
08-25-2014 11:43 AM
"If I change my DNS to 8.8.8.8, everything goes back to working fine. Put OpenDNS back and that site and those apps stop working again. So that's pretty much singles out OpenDNS."
Certainly. Google doesn't have any content filtering or blocking at all, but OpenDNS does according to your individual settings.
"Why is OpenDNS blocking these sites?"
Because you configured your OpenDNS settings to block these sites. OpenDNS doesn't block them by default.
These sites load content from many domains, especially also CDN domains. I do not believe you have blocked only adobe.com, spotify.com and doubleclick.net in your "always block" list.
Visit your blocked domains stats to see what domains are still blocked but maybe needed to access content.
https://dashboard.opendns.com/stats/all/blockeddomains
"Yeah for FamilyShield it is blocking webmail too"
Oops, if you want to block only adobe.com, spotify.com and doubleclick.net, then you must not use the FamilyShield resolver addresses, but you must use the normal OpenDNS resolver addresses. FamilyShield blocks a whole bunch of categories, not matter what you configure.
Also, you didn't mention that you flushed your caches after each settings change. You must!
https://support.opendns.com/entries/26336865-Clearing-the-DNS-Cache-on-Computers-Servers-and-Web-Browsers
Still having problems? Post the complete plain text output of the following diagnostic commands here:
nslookup -type=txt debug.opendns.com.
nslookup watchdisneyxd.go.com.
nslookup www.siriusxm.com.
nslookup www.espn.com.
08-25-2014 11:59 AM
"Because you configured your OpenDNS settings to block these sites."
No, I didn't. As I stated my filter is set to NONE. I only added those domains to always block. Also, as I stated I removed two of them and now only adobe.com is listed. Here:
http://www.tec-systems.com/external/opendns.png
"Oops, if you want to block only adobe.com, spotify.com and doubleclick.net...."
That was someone else.
"Also, you didn't mention that you flushed your caches after each settings change. You must!"
Yes, I clear my cache after waiting 30 minutes after changes.
Debug command:
Server: ad1.xxxxxx.com
Address: 10.10.10.204
Non-authoritative answer:
debug.opendns.com text =
"server 3.pao"
debug.opendns.com text =
"flags 20 0 2F6 0"
debug.opendns.com text =
"originid 16102601"
debug.opendns.com text =
"actype 2"
debug.opendns.com text =
"bundle 4926781"
debug.opendns.com text =
"source 74.x.x.x:21999"
Picking one (disney):
Server: ad1.xxxxx.com
Address: 10.10.10.204
Non-authoritative answer:
Name: dxd-prod-site-1042970201.us-east-1.elb.amazonaws.com
Addresses: 107.20.175.27
107.21.127.206
Aliases: watchdisneyxd.go.com
dxd-prod-site.aws.seabc.go.com
08-25-2014 12:19 PM
Good, but this watchdisneyxd.go.com (real name: dxd-prod-site-1042970201.us-east-1.elb.amazonaws.com, alias: dxd-prod-site.aws.seabc.go.com) is clearly not blocked by OpenDNS, but the real IP addresses 107.20.175.27 and 107.21.127.206 are returned. If it still looks like being blocked, it must be something else, not OpenDNS. Can you post a screen shot of the block page you're seeing? (You can attach it here too.)
Your IP address 74.x.x.x is registered with OpenDNS network ID 16102601. You should find this number in the URL when you're at your dashboard settings for this network.
08-25-2014 12:39 PM
This kept popping up in the blacklist:
Clearly Macromedia is owned by Adobe but I DO NOT have that domain listed in my blocked domains. Yet it's getting blocked anyway. I highly suspect the Disney site and those apps are requiring information from that domain and are failing to run when it can't access them.
So right back to my original question....Open DNS blocking more than it should? Why is it blocking macromedia.com?
Adding macromedia.com to my allow list didn't help.
So in a round about way, blocking adobe.com is causing various video streaming sites and apps to not function.
08-25-2014 12:49 PM
"fpdownload2.macromedia.com"
"but I DO NOT have that domain listed in my blocked domains."
Ha, this is what you thinkg! You do have it in your block list!
nslookup fpdownload2.macromedia.com.
Server: dns1.local.prv
Address: 10.165.161.12
Non-authoritative answer:
Name: a1293.d.akamai.net
Addresses: 95.101.0.83
95.101.0.88
Aliases: fpdownload2.macromedia.com
fpdownload2.wip4.adobe.com
fpdownload.macromedia.com.edgesuite.net
See that one of the aliases is fpdownload2.wip4.adobe.com ? Therefore you have it blocked with your settings! For sure, OpenDNS also blocks the aliases, else users would easily circumvent OpenDNS by using them.
08-25-2014 02:43 PM
You know, I'm starting to get pissed off by your attitude. So far you've done absolutely nothing to help other then tell me everything is my fault/problem and that I've done things that I've not done.
***I*** did NOT have it blocked. OpenDNS is then blocking aliases which means they are blocking MORE than expected. Exactly what I hinted to with my original question. So then in fact blocking a domain could result in blocking many other domains. That's not exactly on the surface of the UI for anyone to know especially when you're asked if you want to turn on additional filtering for that domain or ONLY THAT DOMAIN.
Even still someone should be able to block adobe then ALLOW specific aliases which isn't working.
08-26-2014 07:01 AM
One area that is often confusing is when CNAME records are involved. A large percent of CNAME records are for content delivery networks which are globally whitelisted because they do not stand on their own; but in this case we've come across a few which were blocked.
To allow the adobe/macromedia download sites, add the wip4.adobe.com domain to the whitelist which will allow the download without unblocking other content. I'd always recommend checking our domain tagging site (http://community.opendns.com/domaintagging/) for information regarding which CNAME records inherit properties from other domains which may cause such blocking. For example, fpdownload2.macromedia.com's page will show that there is an adobe.com CNAME which may cause an unexpected block due to a CNAME record (https://domain.opendns.com/fpdownload2.macromedia.com). Since the CNAME record also includes the target in its DNS lookup, therefore it is also captured in the DNS process and would cause a block if the target record from the CNAME were blocked.
Since this is tricky, the stats for your network for blocked domains is a great place to start - and checking these domains at the domain tagging site is a great place to locate what CNAME record may be causing the issue.
08-26-2014 08:43 AM
Excellent, thank you Alexander!
I'll play with wip4.adobe.com. Hopefully that's not responsible for Adobe app updates as that's why it's blocked in the first place. None of our users are able to install applications yet all the adobe apps love to tell my users an update is available. So they download and execute only to be told they can't. Enter a ton of support tickets. We've been happy with the block so far but noticed all these oddball apps and sites not working. I wanted to get to the bottom of it before I ran into something else we couldn't do.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide