Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 Access Denied on several websites, DNS cache or proxy cache issue?

views
     
TSruffstuff
post Feb 9 2019, 01:48 PM, updated 7y ago

Look at all my stars!!
*******
Senior Member
3,345 posts

Joined: Jan 2003
I've come across this annoyances. Googling does not help. There are people experience similar problem and there is a 'solution' of it. Which is restarting your router.

user posted image

One thing, i could not replicate the problem to find the root cause on what triggering this problem. But this problem will happened twice or more within a week. My solution is restarting PPPOE connection and this will resolve. Not all sites is returning the access denied. Most sites working fine. These are the sites that give the access denied error

https://www.cimbclicks.com.my/
https://store.steampowered.com/
https://www.playstation.com/
https://www.jbhifi.com.au/

Things that i tried which is NOT working to resolve the issue.

1. Flushing DNS at client level
2. Flushing DNS at router level
3. Change DNS server at client level
4. Change DNS server at router level

5. Tried different browser (pc/laptop/smartphone) all same problem
6. Change router.


Thing i haven't tried is to force traffic on vpn tunnel when the problem happen. I would assume this could resolve the site. I'm expecting there some issue with https traffic that might cause the issue. I do some port forward on port 443 for my ssh connection. That might be the problem, but i have doubts because only these 3 sites that give me problem.

Some DNS test using several DNS resolver. All access denied.

Google DNS:
user posted image

Cloud Flare:
user posted image

TM DNS:
user posted image


I did fiddler capturing the https traffic. There is some problem with the https caching where it is expired. Not an expert about https caching, if anyone can explain why it is expired?
user posted image

user posted image

This post has been edited by ruffstuff: Feb 10 2019, 10:14 AM
SUSifourtos
post Feb 9 2019, 01:54 PM

Look at all my stars!!
*******
Senior Member
2,256 posts

Joined: Feb 2012



U need ipv4

Not modem lah

Check whatismyip

If u only got ipv6

U cant access ipv4 website


Keep switch until u got ipv4
se7en
post Feb 9 2019, 02:05 PM

resistance is futile
Group Icon
Admin
1,806 posts

Joined: Jan 2003
From: Captain's Cabin, Black Pearl

what is your originating IP? CIMBclicks specifically is blocking a lot of IP's from outside Malaysia since late December after we highlighted their security issues. This block is on their own servers, so its not a DNS issue. You are reaching CIMBClicks servers, but the server itself is throwing up a forbidden response due to either your originating IP or some other header from your browser that it is rejecting.

@ifourtos i don't think there is any ISP's out there which only gives you IPV6 without IPV4 at this point in time.
TSruffstuff
post Feb 9 2019, 05:12 PM

Look at all my stars!!
*******
Senior Member
3,345 posts

Joined: Jan 2003
QUOTE(se7en @ Feb 9 2019, 02:05 PM)
what is your originating IP? CIMBclicks specifically is blocking a lot of IP's from outside Malaysia since late December after we highlighted their security issues. This block is on their own servers, so its not a DNS issue. You are reaching CIMBClicks servers, but the server itself is throwing up a forbidden response due to either your originating IP or some other header from your browser that it is rejecting.

@ifourtos i don't think there is any ISP's out there which only gives you IPV6 without IPV4 at this point in time.
*
It is TM dynamic IP.

[admin@MikroTik] /ip address> print
Flags: X - disabled, I - invalid, D - dynamic
# ADDRESS NETWORK INTERFACE
0 ;;; defconf
192.168.1.1/24 192.168.1.0 ether2
1 D 42.191.27.228/32 10.233.33.38 pppoe-out1


When i do reconnect my PPPOE (which is much faster than rebooting router), and been assigned new IP, the problem got resolved. I want to believe the problem is not at ISP level, so im trying to replicate and find how to trigger the access denied thing. I don't think it is application layer issue. Should be somewhere on the transport layer.
TSruffstuff
post Feb 10 2019, 10:13 AM

Look at all my stars!!
*******
Senior Member
3,345 posts

Joined: Jan 2003
*Updated site list.
TSruffstuff
post Feb 10 2019, 10:20 AM

Look at all my stars!!
*******
Senior Member
3,345 posts

Joined: Jan 2003
QUOTE(se7en @ Feb 9 2019, 02:05 PM)
what is your originating IP? CIMBclicks specifically is blocking a lot of IP's from outside Malaysia since late December after we highlighted their security issues. This block is on their own servers, so its not a DNS issue. You are reaching CIMBClicks servers, but the server itself is throwing up a forbidden response due to either your originating IP or some other header from your browser that it is rejecting.

@ifourtos i don't think there is any ISP's out there which only gives you IPV6 without IPV4 at this point in time.
*
It could be that these sites is blocking range of IPs for certain period? It looks like it is not only me. So it must be at the ISP/server level.
darkstar89
post Mar 24 2019, 02:13 AM

Getting Started
**
Junior Member
80 posts

Joined: Nov 2010
i got similar problem

cant access your list and this also

asus.com
www.jdsports.my
ikea.com

for now only solution is restart router. After few hour or 1 day got problem back.
already disable ipv6 on router and my pc

any solution?
TSruffstuff
post Mar 24 2019, 10:10 AM

Look at all my stars!!
*******
Senior Member
3,345 posts

Joined: Jan 2003
QUOTE(darkstar89 @ Mar 24 2019, 02:13 AM)
i got similar problem

cant access your list and this also

asus.com
www.jdsports.my
ikea.com

for now only solution is restart router. After few hour or 1 day got problem back.
already disable ipv6 on router and my pc

any solution?
*
no solution. Changing ip is the workraound now.
soonwai
post Mar 24 2019, 02:48 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


Do you always get 42.191.0.0/16?

I seem to hear a lot of problems for this range of IPs.

I never get 42 on my pppoe so can’t really check.
DuitNow
post Mar 24 2019, 07:09 PM

On my way
****
Junior Member
597 posts

Joined: Oct 2018
I havent even seen 42.xxx.xxx.xxx ip range yet. I this range malaysia ips?
TSruffstuff
post Mar 24 2019, 09:28 PM

Look at all my stars!!
*******
Senior Member
3,345 posts

Joined: Jan 2003
QUOTE(soonwai @ Mar 24 2019, 02:48 PM)
Do you always get 42.191.0.0/16?

I seem to hear a lot of problems for this range of IPs.

I never get 42 on my pppoe so can’t really check.
*
QUOTE(DuitNow @ Mar 24 2019, 07:09 PM)
I havent even seen 42.xxx.xxx.xxx ip range yet. I this range malaysia ips?
*
I've compiled few IPs that is broken. I'm not sure if the IPs work on certain period or just doesn't work with those websites.
42.191.68.42
42.191.27.228
42.191.90.123
42.191.33.142
42.191.9.11
42.191.49.27
42.191.43.220


Not all 42.191.x.x ips broken. I'm now on 42.191.x.x ips, and it works fine. And the issue seems to be less frequent now. Haven't encounter since few weeks.
SilentVampire
post Mar 24 2019, 09:59 PM

Networking Enthusiast
*******
Senior Member
5,714 posts

Joined: Mar 2007



QUOTE(DuitNow @ Mar 24 2019, 07:09 PM)
I havent even seen 42.xxx.xxx.xxx ip range yet. I this range malaysia ips?
*
Yes, TM owns the range of 42.191.0.0 - 42.191.127.255, so they are currently using it now.

QUOTE(ruffstuff @ Mar 24 2019, 09:28 PM)
I've compiled few IPs that is broken.  I'm not sure if the IPs work on certain period or just doesn't work with those websites.
42.191.68.42
42.191.27.228
42.191.90.123
42.191.33.142
42.191.9.11
42.191.49.27
42.191.43.220
Not all 42.191.x.x ips broken.  I'm now on 42.191.x.x ips, and it works fine.  And the issue seems to be less frequent now. Haven't encounter since few weeks.
*
Yea, that's pretty much all 42.191.0.0/16 IP range that is having issues.

This post has been edited by SilentVampire: Mar 24 2019, 10:04 PM
soonwai
post Mar 24 2019, 10:45 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(DuitNow @ Mar 24 2019, 07:09 PM)
I havent even seen 42.xxx.xxx.xxx ip range yet. I this range malaysia ips?
*
That address space used to belong to Webe. Now TM, of course. But seems like only certain areas will get it. I've never been assigned that before. Usually get 1, 60, 175, etc... but never 42.
rioven
post Mar 25 2019, 02:21 AM

Enthusiast
*****
Senior Member
975 posts

Joined: Sep 2004
From: Setapak



I have no problem except jbhifi (access denied), and im almost on 42.xxx.xxx.xxx ip range since late October last year.

p/s: now im on 42.190.xxx.xxx ip range
TSruffstuff
post Mar 25 2019, 07:46 AM

Look at all my stars!!
*******
Senior Member
3,345 posts

Joined: Jan 2003
QUOTE(rioven @ Mar 25 2019, 02:21 AM)
I have no problem except jbhifi (access denied), and im almost on 42.xxx.xxx.xxx ip range  since late October last year.

p/s: now im on 42.190.xxx.xxx ip range
*
Jb hifi site block entire geo ips. Can see in the header. You need vpn to access jbhifi.
khalil
post Jul 9 2020, 09:47 PM

Getting Started
**
Junior Member
121 posts

Joined: Nov 2005
i got this problem now. using google chrome. access denied to cimbclicks

but if using firefox or edge, no problem.

so its not IP problem, but browser ?
9876789
post Jul 26 2020, 12:22 AM

lost soul
*****
Senior Member
866 posts

Joined: Jan 2003
From: KL


.

This post has been edited by 9876789: Aug 31 2021, 07:07 PM
acer2u
post Oct 28 2020, 04:47 PM

New Member
*
Junior Member
9 posts

Joined: Apr 2008
Hi i found the solution for this problem.

First of all i also got access denied if iwant to access cimbclicks.com.my website. Similar with in the picture on 1st thread. However i can access it via edge and internet explorer i guess it must something wrong with mozilla firefox.

I try to access cimb biz channel . No problem also no problem with cimbclicks.com.sg

So what i did i click cimbclicks.com.my and click on the padlock at the url ( usually for secure https) link it will show padlock.

Then i go to site setting

Then i click clear data and reset permission.

It solved
M4YH3M
post May 11 2021, 03:25 PM

Getting Started
**
Junior Member
67 posts

Joined: Aug 2009


QUOTE(acer2u @ Oct 28 2020, 04:47 PM)
Hi i found the solution for this problem.

...

So what i did i click cimbclicks.com.my and click on the padlock at the url ( usually for secure https) link it will show padlock.

Then i go to site setting

Then i click clear data and reset permission.


It solved
*
Thanks for the guide. It works!
jeffchoi73
post Nov 22 2023, 12:21 PM

New Member
*
Newbie
1 posts

Joined: Mar 2016
Hi,

I had the same problem but clear data and reset permission and reboot router did not work.

What works for me was to clear cache.


QUOTE(acer2u @ Oct 28 2020, 04:47 PM)
Hi i found the solution for this problem.

First of all i  also got access denied if iwant to access cimbclicks.com.my website. Similar with in the picture on 1st thread. However i can access it via edge and internet explorer i guess it must something wrong with mozilla firefox.

I try to access cimb biz channel . No problem also no problem with cimbclicks.com.sg

So what i did i click cimbclicks.com.my and click on the padlock at the url ( usually for secure https) link it will show padlock.

Then i go to site setting

Then i click clear data and reset permission.

It solved
*

 

Change to:
| Lo-Fi Version
0.0252sec    0.56    5 queries    GZIP Disabled
Time is now: 20th December 2025 - 07:10 PM