National Center for Biotechnology Information - blocked no matter what
-
Been trying to unblock the webiste National Center for Biotechnology Information (https://www.ncbi.nlm.nih.gov/). No luck. Disabled pfblockerNG, Disabled DNSSEC, Disabled rules related to DNS, Disabled DNS rules in NAT.
Would appreciate anyones help.
-
@anishkgt I am thinking they use DoH for a site like teams does. For Microsoft Teams if you block every DoH by way of mime it won’t work as it requires a DoH site and will not allow use of local DNS. Maybe that site is doing the same thing.
-
@JonathanLee That is also disabled. I've not enabled it DoH/DoT/DoQ Blocking is set disabled.
-
@anishkgt Try a different DNS see if that fixes it
-
@anishkgt that doesn't resolve..
maybe you have a typo?
Prob one of the sites doge took down.. But nih.gov does not even report any NS.. Its not pfsense blocking you
-
@johnpoz Searching ncbi on google retruns results and the first result is the website i linked. Seems to working on the phone when not on wifi. Wife's gonna killa me with my setup here
-
setting the above resolves the problem. But what was the root cause ?
-
@anishkgt its working now for NS, but they clearly are still having issues
https://dnsviz.net/d/www.ncbi.nlm.nih.gov/dnssec/
Maybe its up for IPv6?
But I resolve it
$ dig www.ncbi.nlm.nih.gov ; <<>> DiG 9.16.50 <<>> www.ncbi.nlm.nih.gov ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 18443 ;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 1232 ;; QUESTION SECTION: ;www.ncbi.nlm.nih.gov. IN A ;; ANSWER SECTION: www.ncbi.nlm.nih.gov. 3365 IN CNAME www.wip.ncbi.nlm.nih.gov. www.wip.ncbi.nlm.nih.gov. 10565 IN A 130.14.29.110 ;; Query time: 5 msec ;; SERVER: 192.168.3.10#53(192.168.3.10) ;; WHEN: Sun Mar 02 12:36:08 Central Standard Time 2025 ;; MSG SIZE rcvd: 103
its working now
Sure like a site doge would go after - they prob shut it down, and then oh our bad - that is not waste that is kind of useful..
-
Same here.
With out of the box pfSense resolver settings I can access it just fine.
It's even native IPv6.
DNSSEC : the entire DNSSEC chain is a indeed a mess, somewhat a proof that the site is legit : only a real 'gov' site can make such a mess out of it