• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Bank site forbidden

Scheduled Pinned Locked Moved General pfSense Questions
10 Posts 3 Posters 3.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • O
    overlord73978
    last edited by Aug 12, 2021, 11:51 PM

    Trying to access the Navy Federal credit union site, but when I log in, I get a blanks screen saying just "Forbidden". I have attached the computer directly to the modem and the site works, but with the pfsense in between, forbidden. I have turned off al forwarding rules, nat rules, opened firewall rules completely in both directions. I don't even have pfblocker installed. The Pfsense is up to date.

    At this point, I'm not even sure what is returning the "Forbidden" that is displayed, I haven't seen anything in logs that would indicate anything being blocked. I'm at a loss. Any ideas?

    J N 2 Replies Last reply Aug 13, 2021, 1:06 AM Reply Quote 0
    • J
      johnpoz LAYER 8 Global Moderator @overlord73978
      last edited by johnpoz Aug 13, 2021, 1:07 AM Aug 13, 2021, 1:06 AM

      Are you running through a vpn?

      I know of nothing in pfsense that would present a "forbidden" page.. But the site could for sure be blocking a vpn IP..

      If your actually using a cable modem, and not a gateway device - and you get a public IP. Also changing your PC for Pfsense would also change the IP you present to the website.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      O 1 Reply Last reply Aug 13, 2021, 1:17 AM Reply Quote 0
      • O
        overlord73978 @johnpoz
        last edited by Aug 13, 2021, 1:17 AM

        @johnpoz Not using a vpn. It is a cable modem, I got the same IP for the computer as I get for the pfsense.

        J 1 Reply Last reply Aug 13, 2021, 2:42 AM Reply Quote 0
        • J
          johnpoz LAYER 8 Global Moderator @overlord73978
          last edited by johnpoz Aug 13, 2021, 2:44 AM Aug 13, 2021, 2:42 AM

          I doubt that, since the mac address of your PC is different than what the mac address of pfsense is..

          The isp dhcp server would hand you a different IP based on mac address..

          Again I know of nothing in pfsense that would present a "forbidden", post a screen shot of this forbidden message... 403 Forbidden is a common message a website would give you when you don't have permission to access..

          https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/403

          A proxy might give you that error - but as you said your not even running pfblocker, so have to assume your not running proxy, etc.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • N
            noplan @overlord73978
            last edited by Aug 13, 2021, 11:48 AM

            @overlord73978

            Looks like u r running squid or pfb as @johnpoz mentioned

            Show us a screen of your installed packages and or running services

            Br Np

            J 1 Reply Last reply Aug 13, 2021, 11:58 AM Reply Quote 0
            • J
              johnpoz LAYER 8 Global Moderator @noplan
              last edited by Aug 13, 2021, 11:58 AM

              I really don't know how he could not know if running proxy - because it wouldn't be doing ssl without some config.. Have to assume a bank login page is via ssl ;)

              My "guess" to the problem is site is blocking his IP, and when he changes out his router for his pc to his modem he would get a different IP..

              As to him saying he has the same IP when he switches... I have never seen a cable connection that would give him the same public IP upon change of mac of device connected to the modem.

              Unless he was cloning his mac address? And his router wan mac was using the same mac as his pc?

              I would like to see this forbidden error page, along with the url being shown in the browser address bar.. I would have to assume its coming from the site, and not anything running on pfsense.. I am not aware of anything he could be running on pfsense that would show him "forbidden" in blocking a site.. And if he was already on the bank site, and then just logging in - why would the url actually change? If it does what is it changing too? from like https://www.bankdomain.com to https://secure.bankdomain.com or something like that?

              example - my bank chase does this
              main site https://www.chase.com, the login domain ends up being https://secure07a.chase.com

              Once we know the fqdn of the signin - we could look to see if anything is blocking that? Maybe he is using some forwarder for dns, and whatever he is using for dns is blocking it and sending him to some forbidden error page??

              All just guessing.. When he switches to his PC, maybe he is just using his isp dns vs whatever dns he has set in pfsense for forwarding?

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              N 2 Replies Last reply Aug 13, 2021, 1:27 PM Reply Quote 1
              • N
                noplan @johnpoz
                last edited by Aug 13, 2021, 1:27 PM

                @johnpoz

                I would like to see this forbidden error page, along with the url being shown in the browser address bar

                Yes yes yes

                The rest I totally agree with you on that...

                1 Reply Last reply Reply Quote 0
                • N
                  noplan @johnpoz
                  last edited by Aug 13, 2021, 1:27 PM

                  This post is deleted!
                  1 Reply Last reply Reply Quote 0
                  • O
                    overlord73978
                    last edited by Aug 16, 2021, 3:08 PM

                    I'm sorry I haven't been able to respond again. Covid came to our house and now I'm quarantined in a hotel. So I'll look into this again next week when I'm back home.

                    Jon, thank you for the reality reminder, there's no reason the pc should get the same IP address and I must have copied something down wrong when checking that. I'll take screenshots when I do get back to it.

                    Thanks for your responses

                    N 1 Reply Last reply Aug 16, 2021, 3:17 PM Reply Quote 0
                    • N
                      noplan @overlord73978
                      last edited by Aug 16, 2021, 3:17 PM

                      @overlord73978

                      Stay healthy

                      1 Reply Last reply Reply Quote 1
                      10 out of 10
                      • First post
                        10/10
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                        This community forum collects and processes your personal information.
                        consent.not_received