Nodered site is blocked india

Wish I'd seen this earlier when I was an a call with GitHub trying to sort out their confusing and largely pointless Enterprise service.

It might solve the issue. But, We don't have control on DNS. Since, it's mostly decided by internet service provider for remote users like me

You arent limited to the DNS that your ISP provides. In fact, I've not used that for decades. There is plenty of choice and several that support modern encrypted DNS connections as well.

2 Likes

No brother.. it still giving issue.

@sdrshnptl
Yes for me as well

Can't access it from workspace. since, have limited access to change the network settings

But, I can access the node-red site in home since I changed the DNS

1 Like

Please share your DNS server address if they are open.
I've tried cloudflare but no luck.

I have also tried to access the Site but was blocked for more than 10 days. I have tweeted to GOI and @node-red regarding it. But no Response from both.

1 Like

Hi @raivens - I did see your tweet, my apologies for not reply directly at the time.

It still isn't clear where the blockage is happening as other users in India have reported they can access the site without problem. That suggests it is dns related - I have seen some mention of problems in India with the CloudFlare dns (1.1.1.1). You could try changing to Google's DNS (8.8.8.8) and see if that helps. That doesn't help users on corporate networks who can't change their DNS settings.

I tried to report it via the webform @Paul-Reed linked to, but couldn't get the form to submit - kept telling me to "enter valid comments" with no hint what was wrong with the comments I had provided.

1 Like

I am on CloudFlare's DNS 1.1.1.1 & 1.0.0.1
Flushed windows DNS cached ipconfig /flushdns
Flushed chrome DNS and sockets chrome://net-internals/

I get this error now.

https://www.ip-lookup.org/location/182.79.218.34

That IP belongs to Bharti Airtel, I would guess that your ISP is doing transparent DNS proxy to intercept requests to 1.1.1.1 and then returning that ip for requests to NodeRED.org in order to block it.

It doesn't look like DNS proxy based on this info now.

Internet connection 1 (with issue)

https://i.imgur.com/Aw87BYE.png
https://i.imgur.com/Ln6CIjp.png
https://i.imgur.com/tBJYYhm.png

Internet connection 2 (nodered.org opens)

https://i.imgur.com/2DQANLb.png
https://i.imgur.com/Enks1ch.png

Q1.. How are they able to change the content of an HTTPS page (MITM)?
Most possibly github pages traffic is unencrypted at some point and that is where the ISP is able to inspect the host headers and change the page content.

It sounds like Github Pages might be doing something similar to how CloudFlare's Flexible SSL works.
Ref: End-to-end HTTPS with Cloudflare - Part 3: SSL options ā€“ Cloudflare Help Center

I have posted to the Cloudflare community forum for any input they may have.

2 Likes

This is an years old problem that we've raised many times with cloudflare. Here's a report from 2016 with comments from cloudflare CEO https://www.medianama.com/2016/07/223-cloudflare-ceo-matthew-prince-airtel-sniffing-data-packets/

Alas, cloudflare hasn't really put their weight to resolve this with Airtel.

Do you only use cloudflare for DNS or also for proxy the content via it? If latter, then you should enable full SSL in case flexible SSL is being used, and that will help in resolving the issue.

2 Likes

Thanks @shantanugoel

I've made some configuration changes as you and some others have suggested. Let's see if they improve matters.

3 Likes

Thanks @knolleary !
It's working now :v:
No need to use VPN!

Thanks @knolleary for your time... We can access the nodered site from any ISP in india

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.