Comcast is blocking certain Cloudflare IPs

What is the name of the domain?

104.21.4.250

What is the error number?

request timed out in traceroute

What is the issue you’re encountering

Website behind cloudflare does not resolve or load, only when accessed from comcast

What steps have you taken to resolve the issue?

Tried different ISP, works fine.

Tried settings to Full (strict) mode as found in another thread suggestion. It did update the IP but it is also blocked.

tracert 104.21.4.250

Tracing route to 104.21.4.250 over a maximum of 30 hops

1 1 ms <1 ms 1 ms 192.168.0.1
2 13 ms 13 ms 12 ms 100.93.110.67
3 13 ms 12 ms 12 ms po-317-340-rur302.troutdale.or.bverton.comcast.net [96.108.65.105]
4 12 ms 12 ms 10 ms po-300-xar02.troutdale.or.bverton.comcast.net [96.216.158.97]
5 * * * Request timed out.
6 * * * Request timed out.
7 * * * Request timed out.
8 * * * Request timed out.
(same result for 30 hops)

What are the steps to reproduce the issue?

Be on comcast. Traceroute to the IP. or any domain associated with the IP from cloudflare.

The problem, as you indicate yourself, is your ISP’s bad decision, with blocking Cloudflare IP addresses from time to time.

You will need to contact Comcast for further remediation.

Thanks for the response. Yes, I agree, I am seeking tips on how to navigate this with the ISP and actually contact the right people, and to prove it’s the ISP so they take this seriously.

This does impact the cloudflare network, so I would hope there could be some attention on the cloudflare side as well considering this comcast network block.

I’ve been on hours of hold with comcast agents and I’m struggling to get anyone to understand I need some IPs unblocked.

I’ve been directed to ‘Customer Security Assurance’ – took about an hour on the phone going back and forth, then another hour on hold waiting for the ‘Internet Repair Department’

If there is some other channel or method to talk to directly with their network team I would appreciate any insights.

FWIW, you could also use Cloudflare Warp for free.

Essentially, WARP is like a proxy or a VPN you could run on your computer and it will bypass Comcast, as long as you can still connect with Cloudflare servers. (which have separated address space from their reverse proxies.)

The official client have some interesting modes of operation, including socks proxy where you can be selective about which hostname to route through Cloudflare. (with a PAC script)

This topic was automatically closed 2 days after the last reply. New replies are no longer allowed.