Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Unable to browse certain websites

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    14 Posts 4 Posters 946 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S
      stephenw10 Netgate Administrator
      last edited by

      Yes, more info required. 😉

      What pointed you to a DNS problem? Sites fail to resolve at clients behind pfSense?

      Try Diag > DNS Lookup in pfSense. Do the same sites resolve on everything configured there?

      What hardware device are you using?

      Steve

      T 1 Reply Last reply Reply Quote 0
      • T
        tscengr @stephenw10
        last edited by

        @stephenw10 @SteveITS

        Sorry for the incomplete info. The reason why it lead me to DNS is because when I statically assign Google DNS it went through. Currently the DNS server assigned on the Netgate 3100 are the following:

        208.67.222.222 - OpenDNS
        208.67.220.220 - OpenDNS
        8.8.8.8 - Google DNS

        I did a Diagnostics > DNSLookup and the screenshot shows below

        Robert_Markel_-DAL.RMWBH.com - Diagnostics_ DNS Lookup.png

        Also, they have a branch office and issue is not happening but it does have a response for 127.0.0.1 not like the uploaded image where it shows 'No Response' for 127.0.0.1

        Already rebooted the pfsense hardware but still the same

        Jeff

        1 Reply Last reply Reply Quote 0
        • T
          tscengr @SteveITS
          last edited by

          @SteveITS said in Unable to browse certain websites:

          @tscengr see https://docs.netgate.com/pfsense/en/latest/troubleshooting/website-access-issues.html

          Any info would help. DNS correct or no? Squarespace, by chance?

          Hardware is: NetGate 3100

          S 1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            Ok, so localhost there (127.0.0.1) is not responding. That's Unbound on the firewall which is what LAN side clients are passed to use by default.

            So is Unbound running? Check Status > Services.

            Is it using the default settings?

            T 2 Replies Last reply Reply Quote 0
            • T
              tscengr @stephenw10
              last edited by

              @stephenw10

              I just did another DNSLookup and this time it now has a response. I went to Dagnostics > Services and UNbound DNS Resolver has a green check though I didn't check this earlier since newbiew to pfsense/ Let me ask if it's now working or still an issue. Thanks for all the help

              Jeff

              1 Reply Last reply Reply Quote 0
              • T
                tscengr @stephenw10
                last edited by

                @stephenw10

                even though it now shows a response, still unable to browse the site.Unbound is running and has a green check

                Jeff

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  Ok, so is DNS failing at the client?

                  What error is shown when you try to go to the site?

                  T 1 Reply Last reply Reply Quote 0
                  • T
                    tscengr @stephenw10
                    last edited by

                    @stephenw10

                    For some reason this morning, it suddenly worked. Really odd situation but thanks for all the help,, may need some video trainings for future tickets I think

                    Jeff

                    1 Reply Last reply Reply Quote 1
                    • S
                      SteveITS Galactic Empire @tscengr
                      last edited by SteveITS

                      @tscengr The reason I asked about Squarespace is because I've been fighting an issue for a few weeks where my home and office cannot connect to Squarespace-hosted sites using HTTPS. Specifically, these IPs:

                      ext-sq.squarespace.com. 151     IN      A       198.185.159.145
                      ext-sq.squarespace.com. 151     IN      A       198.49.23.144
                      ext-sq.squarespace.com. 151     IN      A       198.185.159.144
                      ext-sq.squarespace.com. 151     IN      A       198.49.23.145
                      

                      I can ping them and HTTP works, but HTTPS fails to connect (times out). We accidentally found it started working late yesterday afternoon, but is not working now. I am confident it's not pfSense related, nor PC related since it happens on phones as well.

                      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                      Upvote 👍 helpful posts!

                      S 1 Reply Last reply Reply Quote 0
                      • S
                        SteveITS Galactic Empire @SteveITS
                        last edited by

                        @SteveITS Sigh, well now that I posted that, I finally tracked it down. Squarespace web server IPs are in the https://raw.githubusercontent.com/jpgpi250/piholemanual/master/DOHipv4.txt list for blocking DoH servers.

                        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                        Upvote 👍 helpful posts!

                        1 Reply Last reply Reply Quote 1
                        • U
                          Uglybrian
                          last edited by

                          @steve, I had the same problem, with that exact list five weeks ago. For me it was blocking sdisf.com. Needless to say, I looked for a new doh list to use.

                          S 1 Reply Last reply Reply Quote 0
                          • S
                            SteveITS Galactic Empire @Uglybrian
                            last edited by

                            @Uglybrian Thanks. Yeah that list just consolidates other lists without editing, but that's disappointing. There are a few Closed issues on the Github site for specific IPs but "all of Squarespace" is a pretty big target.

                            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                            Upvote 👍 helpful posts!

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.