uamallowed paypal does not open

Hi everyone,

i'm running coovachilli 1.2.9 in layer 3 mode with vlan enable. I'm trying to put paypal.com on uamallowed, but the result is that it works only some times. other times it just hang like if it wasn't on uamallowed

on main.conf
uamallowed www.paypal.com,66.211.168.0/24,64.4.241.0/24,216.113.188.0/24
uamallowed www.paypalobjects.com,88.221.0.0/16,84.53.0.0/16,67.133.200.0/22,72.246....
uamallowed paypal.112.2o7.net,216.52.17.0/24,70.42.134.0/24,128.242.125.0/24
uamanydns
uamanyip
layer3
statip X.X.X.X/255.255.255.0
vlan "60"
uamdomain .paypal.com
uamdomain .paypalobjects.com
uamdomain .mediaplex.com
uamdomain .112.2o7.net

on config
HS_UAMALLOW=(...),www.paypal.com,,66.211.168.0/24,64.4.241.0/24,216.113.188.0/24,www.paypalobjects.com,88.221.0.0/16,84.53.0.0/16,67.133.200.0/22,
72.246.0.0/15,paypal.112.2o7.net,216.52.17.0/24,70.42.134.0/24,128.242.125.0/24,216.113.160.0/19,69.58.176.0/20

On this line you have 2

On this line you have 2 commas, one is the rule...

*****************
HS_UAMALLOW=(...),www.paypal.com,,66.211.168.0/24,64.4.241.0/24,216.113.188.0/24,www.paypalobjects.com,88.221.0.0/16,84.53.0.0

*****************

as the two commas appear to be next to the paypal entry, its a likely suspect......unlesits a typo on your part..

IP change

Hi,

thanks for the feedback. Unfortunately this was a typo error when i was copying the text.
Digging on the paypal IP's, i've found out the correct combination that is working at the moment

i've just added 173.0.0.0/16 and everything start working ok

i'm not sure if we can reduce the ip range, but for now it's working

Here's a link to what paypal

Here's a link to what paypal ips are used. Might not be entirely complete, but ought to be as it is PP's own list.

https://ppmts.custhelp.com/app/answers/detail/a_id/92

Also this list is updated now and then, so you might want to keep an eye out if your PP system stops working....:-).

Awesome

Finding an updated list of paypal that actualy explains everything and list all the correct IP's, including the Akamai change is indeed awesome.

Thank you very much for that link. I've already put it in the bookmarks

Cheers