PFSense blocking Visible.com site only
-
Hello
Have a home network setup and attempting to access the website for https://www.visible.com/. However, the site says down with server error - or so I originally thought it was being rebooted.It appears that PFSense is blocking access to this one site for everything behind the firewall on the network. Suspect PFSense anyway as do have some UBNT wifi gear which I'm on. Tested by turning off wifi on mobile phone and can get to the site( carrier network). Tested behind PF on two Wifi SSIDs using two computers operating systems (Linux & Mac) and two different phone systems (Android & Apple)- all blocked.
Traditionally an Nginx error (502 seems to be the code) on server but here appears tied to the PF Sense and blocking.
I was running PF CE 2.6.0. Restarted DNS, rebooted hardware and nothing so far. Couldn't find anything in settings to block it but I'm not an expert in firewalls or PFSense. Even went and got a key to use PFSense + -- did the upgrade and am still being blocked when behind PF Sense.
I'm looking for any recommendations on resolution and/or next steps?
Thank you for recommendations / help!
-
@pbf343 said in PFSense blocking Visible.com site only:
www.visible.com/
working here - that sure doesn't look like any sort of error that would be shown/caused by pfsense.. That looks like an error their server sent.
If pfsense was having a problem resolving that - you would get some sort of dns, host name could not be found sort of error in your browser. Or just a timeout sort of error if you could not get there because blocked by firewall rule.
Such an error - try again in 30 seconds would point to server having an issue, overloaded or something and sending that info.
-
@johnpoz That looks to me like Visible's proxy or load balancer is misbehaving for a certain region.
It works here, too, in the north central region of the US.
-
Yes I agree and thought it was originally. Most common reasons for 502 error is server side but also can be network related.
Turns out NOT PF Sense ("probably not PF " == NOT PF) but probably the Ubiquity Gear. I just got out some cables and connect the Mac to physical port and turned off Wifi. Got there without issue.
The DNS, Whois, etc. seems to show different items in that the Registration appears to be domains@bevisible.com with an IP of 35.190.57.191. However, the certificate today looks different than the one from yesterday.
Originally on their website and logged into the site with Chat when tried a link of the page. Got the error. Thus, thought they went down. Now makes me wonder if something is spoofed from UBNT gear.
Thanks for looking! On to UBNT configs. ;-)