如何判断Comcast是否屏蔽IP?CentOS7站点跨ISP访问异常求助
Hey Dave, thanks for sharing the details—let’s break down why your site (http://68.66.205.103) is unreachable on Comcast/RCN but works on AT&T/Tor, and walk through actionable steps to fix this.
First, the key clue here is that Tor works on Comcast: this confirms your site is online and functional, so the problem is almost certainly related to Comcast/RCN’s network routing or IP blocking (since Tor routes traffic through different exit nodes that aren’t subject to the same restrictions).
Step 1: Narrow Down the Block Type
Since you’re accessing via raw IP (not a domain), DNS issues are out of the question. Let’s confirm whether it’s a full IP block or a port-specific block:
- On a Comcast/RCN device, run these commands to test connectivity to your site’s ports (80 for HTTP):
If the connection times out, traffic is being blocked before reaching your server. If it connects but you don’t get an HTTP response, it might be a WAF/HTTP-level restriction (less likely since Tor works).# Test TCP connection to port 80 telnet 68.66.205.103 80 # Or use netcat for more verbose output nc -zv 68.66.205.103 80 - Run a TCP traceroute (instead of ICMP, which ISPs often block) to see where the traffic dies:
Compare this to your AT&T traceroute—look for the last hop where packets stop propagating (this will point to either a Comcast router or a hop before your server).traceroute -T 68.66.205.103
Step 2: Check Server-Side Security Rules
Your A2 Hosting server might be blocking Comcast/RCN IP ranges by accident:
- Log into your A2 Hosting control panel and check the firewall (most use CSF/LFD). Look for any blocked IP ranges that match Comcast/RCN’s ASNs (Comcast is ASN 7922, RCN is ASN 10796).
- Review your server’s access logs (
/var/log/httpd/access_logor/var/log/apache2/access.logdepending on setup) for any entries from Comcast IPs. If you see no entries at all, traffic isn’t reaching your server. If you see 403/503 errors, your WAF or Apache config might be blocking those requests. - Contact A2 Hosting support and ask them to:
- Verify their network ACLs aren’t restricting Comcast/RCN traffic
- Run a reverse traceroute from your server to a Comcast IP to check for routing issues
Step 3: Engage Comcast/RCN Support
If your traceroute shows the block is happening at a Comcast hop:
- Gather your TCP traceroute results and share them with Comcast’s technical support. Be specific about the issue (site works on other ISPs/Tor, fails on their network) and ask them to check if the IP 68.66.205.103 is blocked in their network or if there’s a routing fault.
- Note: ISPs rarely admit to intentional blocking, but they’ll often fix routing issues if presented with clear evidence.
Step 4: Rule Out Edge Cases
- If you’re using any WAF or GeoIP restrictions (even via A2’s built-in tools), double-check that you haven’t accidentally blocked regions covered by Comcast/RCN. Tor exit nodes might be in allowed regions, which would explain why it works.
- Check your server’s TCP connection limits: If Comcast users are hitting a connection cap, you might see timeouts, but this is unlikely since AT&T works fine. You can verify with
ss -sto check active connections.
Final Takeaway
Given the Tor workaround, the most likely culprits are:
- Comcast/RCN has a routing issue preventing traffic to your IP
- Your server’s firewall or A2’s network has mistakenly blocked Comcast/RCN IP ranges
Start with the TCP traceroute and server log checks—those will give you the clearest direction to resolve this.
内容的提问来源于stack exchange,提问作者Dave

