Are you getting 403's when downloading? Please read here first

Hi,

sadly our company (or the whole hoster?) got blocked too despite being located in germany. Also our hoster is only doing business with us (kind of sub company).

IP: 89.191.92.0/25
Location: Germany

curl -qs ipinfo.io/89.191.92.5                                                                              ✔  1001  10:22:04
{
  "ip": "89.191.92.5",
  "city": "Mainz",
  "region": "Rheinland-Pfalz",
  "country": "DE",
  "loc": "49.9842,8.2791",
  "org": "AS34624 Megaspace Internet Services GmbH",
  "postal": "55118",
  "timezone": "Europe/Berlin",
  "readme": "https://ipinfo.io/missingauth"
}

If there are other reasons why we should have been landed on the block list please tell me :slight_smile:

Best regards

Hello, when I try to get elastic, I see a 403 error. Please unlock access

curl ipinfo.io
{
  "ip": "77.91.127.107",
  "city": "Meppel",
  "region": "Drenthe",
  "country": "NL",
  "loc": "52.6958,6.1944",
  "org": "AS52000 MIRholding B.V.",
  "postal": "7941",
  "timezone": "Europe/Amsterdam",
  "readme": "https://ipinfo.io/missingauth"
}

@niemanz the ASN that was added was for 2a03:94e0::/32. It seems that 2a03:94e0::/30 is not a valid range?

@warkolm sorry, but it is still not working.

Here is a detailed example from a random server from the 2a03:94e0::/32 subnet:

Server IP: 2a03:94e0:ffff:194:32:107:0:92 belongs to 2a03:94e0::/32 and just in case also verify this on bgp.he.net

$ curl -6L ifconfig.co
2a03:94e0:ffff:194:32:107:0:92

$ wget elastic.co
--2022-11-23 20:23:44--  http://elastic.co/
Resolving elastic.co (elastic.co)... 2600:1901:0:1f6d::, 34.107.161.234
Connecting to elastic.co (elastic.co)|2600:1901:0:1f6d::|:80... connected.
HTTP request sent, awaiting response... 308 unknown
Location: https://elastic.co:443/ [following]
--2022-11-23 20:23:44--  https://elastic.co/
Connecting to elastic.co (elastic.co)|2600:1901:0:1f6d::|:443... connected.
HTTP request sent, awaiting response... 403 Forbidden
2022-11-23 20:23:44 ERROR 403: Forbidden.

$ wget https://artifacts.elastic.co/downloads/beats/elastic-agent/elastic-agent-8.5.0-linux-x86_64.tar.gz
--2022-11-23 20:28:16--  https://artifacts.elastic.co/downloads/beats/elastic-agent/elastic-agent-8.5.0-linux-x86_64.tar.gz
Resolving artifacts.elastic.co (artifacts.elastic.co)... 2600:1901:0:1d7::, 34.120.127.130
Connecting to artifacts.elastic.co (artifacts.elastic.co)|2600:1901:0:1d7::|:443... connected.
HTTP request sent, awaiting response... 403 Forbidden
2022-11-23 20:28:16 ERROR 403: Forbidden.

IP: 109.252.143.62
Location: Moscow/Russia

IP: 2a00:1370:8180:4f2f:d4d7:781c:46f4:445a
Location: Moscow/Russia

IP: 88.218.248.172
Location: Amsterdam/Netherlands

IP: 185.200.190.81
Location: Helsinki/Finland

First two are the just ipv4 and ipv6 of the same network.
Using Russian and EU networks independently returns 403 from web download and also via brew installation.

Why is this happening?

@warkolm could you please unblock the IP range mentioned by @TuningYourCode ? It blocks at the moment at lot of processes.

Best regards!

Hi!

Status code: 403 for https://artifacts.elastic.co/packages/5.x/yum/repodata/repomd.xml (IP: 34.120.127.130)

  • ip:"46.22.211.87",
  • hostname:"46.22.211.87.wavecom.ee",
  • city:"Tallinn",
  • region:"Harjumaa",
  • country:"EE",
  • loc:"59.4370,24.7535",
  • org:"AS34702 Aktsiaselts WaveCom",
  • postal:"10111",
  • timezone:"Europe/Tallinn",

Sorry @warkolm, I know it must be time consuming and a bit tiring. But did you receive my request by private message sent two weeks ago?

I have a French IP to unlock for a dedicated server rented from OVH.

Thank you very much for your work and your time.

@SuperTux88 can you advise now if it's ok?

@braidner @Althea_Vestrit you should be good to go now.

@ewasser yours was via PM but should also be ok now.

Nope, still blocked :frowning:

Thanks, but still blocked to me. :scream:

Hi Could you pleas unblock my servers

curl -qs ipinfo.io
{
  "ip": "51.83.228.154",
  "hostname": "gateway-demo.promesaonline.com",
  "city": "Warsaw",
  "region": "Mazovia",
  "country": "PL",
  "loc": "52.2298,21.0118",
  "org": "AS16276 OVH SAS",
  "postal": "00-002",
  "timezone": "Europe/Warsaw",
  "readme": "https://ipinfo.io/missingauth"
}

curl -qs ipinfo.io
{
  "ip": "146.59.25.195",
  "hostname": "ip195.ip-146-59-25.eu",
  "city": "Warsaw",
  "region": "Mazovia",
  "country": "PL",
  "loc": "52.2298,21.0118",
  "org": "AS16276 OVH SAS",
  "postal": "00-002",
  "timezone": "Europe/Warsaw",
  "readme": "https://ipinfo.io/missingauth"
}

curl -qs ipinfo.io
{
  "ip": "146.59.6.175",
  "hostname": "ip175.ip-146-59-6.eu",
  "city": "Warsaw",
  "region": "Mazovia",
  "country": "PL",
  "loc": "52.2298,21.0118",
  "org": "AS16276 OVH SAS",
  "postal": "00-002",
  "timezone": "Europe/Warsaw",
  "readme": "https://ipinfo.io/missingauth"
}

Hi @warkolm, could you please unblock my server?

  "ip": "51.83.228.154",
  "hostname": "gateway-demo.promesaonline.com",
  "city": "Warsaw",
  "region": "Mazovia",
  "country": "PL",
  "loc": "52.2298,21.0118",
  "org": "AS16276 OVH SAS",
  "postal": "00-002",
  "timezone": "Europe/Warsaw",
  "readme": "https://ipinfo.io/missingauth"
}```

Hello!

We're an international medical company with one of our dc's located in Russia/Moscow.
Would You please kindly remove our ip address 185.11.199.133 from the ban list?
We're getting 403 errors and this affects our prod environment badly...
We have nothing to do with politics, absolutely.
Thank's in advance!

We are unable to allow any RU based IP access at all sorry.

@warkolm , looks like 46.22.211.87 is still restricted - can you please unblock it?

Can You then please allow at least 194.87.82.5?
This is our co-loc part in Netherlands DC and it seems like it is also in a ban list
Thank You very much in advance!

@niemanz we cannot see any records of this IP being denied against our systems, which I am being told indicates it's not reaching us at all, as we log a denied attempt for visibility purposes.

IP: 185.4.75.56
Location: Estonia, Tallinn

https://artifacts.elastic.co/packages/7.x/yum/repodata/primary.xml.gz: [Errno 14] HTTPS Error 403 - Forbidden
curl ipinfo.io
{
  "ip": "185.4.75.56",
  "city": "Tallinn",
  "region": "Harjumaa",
  "country": "EE",
  "loc": "59.4370,24.7535",
  "org": "AS198068 P.A.G.M. OU",
  "postal": "10111",
  "timezone": "Europe/Tallinn",
  "readme": "https://ipinfo.io/missingauth"
}