# Bahn.de extreemely slow

**URL:** <https://discourse.pi-hole.net/t/bahn-de-extreemely-slow/6094>\
**Category:** General\
**Created:** [December 22, 2017, 7:14pm UTC](https://discourse.pi-hole.net/t/bahn-de-extreemely-slow/6094 "2017-12-22T19:14:12Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![MontgomeryB](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/m/71e660/32.png) [@MontgomeryB](https://discourse.pi-hole.net/u/MontgomeryB)\
**Post date:** [December 22, 2017, 7:14pm UTC](https://discourse.pi-hole.net/t/bahn-de-extreemely-slow/6094/1 "2017-12-22T19:14:13Z")

</div>

Hi,  
www.bahn.de is very, very slow and it is still the same problem ([PiHole Limits Functionality- How to Fix?](https://discourse.pi-hole.net/t/pihole-limits-functionality-how-to-fix/1525)) and it's definitely pi-hole.  
If I deactivate pi-hole, then the bahn.de site works wonderfull. As soon as pi-hole is activated, the pages takes ages.  
Chrome, Edge, Firefox - all the same issue.

any idea?

greets  
Monti

---

<div class="post-metadata">

**Author:** ![werkkzeug](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/w/59ef9b/32.png) [@werkkzeug](https://discourse.pi-hole.net/u/werkkzeug)\
**Post date:** [December 22, 2017, 8:06pm UTC](https://discourse.pi-hole.net/t/bahn-de-extreemely-slow/6094/2 "2017-12-22T20:06:04Z")

</div>

I can use the website with no problems in Chrome (desktop) + Edge (Win10 mobile).

Are you blocking any of these?

> hdshlsdbbahn-vh.akamaihd.net  
> www.img-bahn.de  
> reiseauskunft.bahn.de  
> rabdc.bahn.de  
> ps.bahn.de  
> www.dbbahnpark.info

---

<div class="post-metadata">

**Author:** ![anon82568829](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/a/ce73a5/32.png) [@anon82568829](https://discourse.pi-hole.net/u/anon82568829)\
**Post date:** [December 22, 2017, 8:41pm UTC](https://discourse.pi-hole.net/t/bahn-de-extreemely-slow/6094/3 "2017-12-22T20:41:54Z")

</div>

I was able to fix it by rejecting https-requests.  
Add a filter rule on your Pi-Hole (or the router in-between) which reject (not blocks!) https-requests to the pihole-host.

---

<div class="post-metadata">

**Author:** ![DL6ER](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dl6er/32/281_2.png) [@DL6ER](https://discourse.pi-hole.net/u/DL6ER)\
**Post date:** [December 22, 2017, 11:16pm UTC](https://discourse.pi-hole.net/t/bahn-de-extreemely-slow/6094/4 "2017-12-22T23:16:56Z")

</div>

@MontgomeryB Just out of curiosity: Do you use any non-standard blocking lists? I cannot see any issues with their page with only the standard lists and no explicit HTTPS rejection rules.

---

<div class="post-metadata">

**Author:** ![MontgomeryB](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/m/71e660/32.png) [@MontgomeryB](https://discourse.pi-hole.net/u/MontgomeryB)\
**Post date:** [December 23, 2017, 9:42am UTC](https://discourse.pi-hole.net/t/bahn-de-extreemely-slow/6094/5 "2017-12-23T09:42:01Z")

</div>

No blocking! Some of them are even whitelisted.

---

<div class="post-metadata">

**Author:** ![MontgomeryB](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/m/71e660/32.png) [@MontgomeryB](https://discourse.pi-hole.net/u/MontgomeryB)\
**Post date:** [December 23, 2017, 9:45am UTC](https://discourse.pi-hole.net/t/bahn-de-extreemely-slow/6094/6 "2017-12-23T09:45:14Z")

</div>

fyi: The mobile version of bahn.de and its ticket order stuff works fine. The desktop versions don't

---

<div class="post-metadata">

**Author:** ![DL6ER](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dl6er/32/281_2.png) [@DL6ER](https://discourse.pi-hole.net/u/DL6ER)\
**Post date:** [December 23, 2017, 11:19am UTC](https://discourse.pi-hole.net/t/bahn-de-extreemely-slow/6094/7 "2017-12-23T11:19:34Z")

</div>

Very weird - I just tried it again and it works flawlessly for me (I'm using the Fahrplanauskunft several times a week). As said, I have no firewall rules in place on my Pi-hole.

---

<div class="post-metadata">

**Author:** ![MontgomeryB](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/m/71e660/32.png) [@MontgomeryB](https://discourse.pi-hole.net/u/MontgomeryB)\
**Post date:** [December 23, 2017, 11:27am UTC](https://discourse.pi-hole.net/t/bahn-de-extreemely-slow/6094/8 "2017-12-23T11:27:36Z")

</div>

strange, indeed.

@anon82568829 - how did you exactly solve your problem? where to config what.

---

<div class="post-metadata">

**Author:** ![anon82568829](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/a/ce73a5/32.png) [@anon82568829](https://discourse.pi-hole.net/u/anon82568829)\
**Post date:** [December 23, 2017, 11:40am UTC](https://discourse.pi-hole.net/t/bahn-de-extreemely-slow/6094/9 "2017-12-23T11:40:15Z")

</div>

@MontgomeryB  
I do not really remember, to be honest.

It was during my first days with pi-hole. I realized very quickly of having issues with (partially) https:// sites. For http there was no issue as Pi-hole properly send some small pics instead of the orignial ad. But obviously Pi-hole could not answer https-requests (as it would have to generate a valid https-certificate to prevent the browsers from mocking).

At this time the request just timed out trying to access [https://ip-of-pihole/](https://ip-of-pihole/) which took ages and often brought the whole page down. There was no one replying to https-requests.

Instead of getting just no answer and waiting for ages (default behaviour) I decided to let the browser know about the fact no one will reply. So the browser knows immediate about "no reply".

So I created a filter rule on the Pi-hole which simply REJECTs (instead of BLOCK) any request to http-Port 443 to the Pi-hole server.

So now the browser gets an immediate reply and knows very quick about not being able to get the requested element (which is an ad because of the IP). and displays all other elements properly.

Since I did this change Nearly every site is running fine and fast.

---

<div class="post-metadata">

**Author:** ![MontgomeryB](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/m/71e660/32.png) [@MontgomeryB](https://discourse.pi-hole.net/u/MontgomeryB)\
**Post date:** [December 23, 2017, 12:21pm UTC](https://discourse.pi-hole.net/t/bahn-de-extreemely-slow/6094/10 "2017-12-23T12:21:40Z")

</div>

> [@anon82568829](#):
>
> rejecting https-requests

Thank you, knebb!

If anyone knows, please give me a hint.

So, @all of you - have a nice winter holiday and a very first-class 2018

cheers  
Monti

---

<div class="post-metadata">

**Author:** ![DL6ER](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dl6er/32/281_2.png) [@DL6ER](https://discourse.pi-hole.net/u/DL6ER)\
**Post date:** [December 23, 2017, 12:38pm UTC](https://discourse.pi-hole.net/t/bahn-de-extreemely-slow/6094/11 "2017-12-23T12:38:12Z")

</div>

> [@anon82568829](#):
>
> There was no one replying to https-requests.

Ah, that may be the difference then. I'm directly getting this when trying to access htps://pi.hole

 ![Screenshot at 2017-12-23 13-31-55](https://discourse.pi-hole.net/uploads/default/original/2X/a/a3d6581454b4babd6ef0fd290646dfcae3baa669.png)

and it should actually be standard when you have no firewall enabled.

@MontgomeryB What device did you install your Pi-hole on?

The following assumes that you are running Raspbian on a Rasbperry Pi (or similar) and have no firewall rules installed. If this is not true we have to negotiate how to properly set up your firewall, but that shouldn't be a big deal!

Solution for Raspbian: Check you actually have n firewall rules installed. Use `sudo iptables -L --line-numbers`, it should show something like

```auto
Chain INPUT (policy ACCEPT)
num target prot opt source destination

Chain FORWARD (policy ACCEPT)
num target prot opt source destination     

Chain OUTPUT (policy ACCEPT)
num target prot opt source destination 

```

if there is anything more, we'll most likely have to deal with that differently.

If there are no firewall rules, you can straightforwardly add the HTTPS `REJECT` rule like this:

```auto
iptables -A INPUT -p tcp --dport 443 -j REJECT

```

If you also use IPv6, add an IPv6 rule as well:

```auto
ip6tables -A INPUT -p tcp --dport 443 -j REJECT

```

> [@MontgomeryB](#):
>
> So, @all of you - have a nice winter holiday and a very first-class 2018

Thanks, same to you (btw, I have never used first class with DB so far 🙂 )

---

<div class="post-metadata">

**Author:** ![MontgomeryB](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/m/71e660/32.png) [@MontgomeryB](https://discourse.pi-hole.net/u/MontgomeryB)\
**Post date:** [December 23, 2017, 2:43pm UTC](https://discourse.pi-hole.net/t/bahn-de-extreemely-slow/6094/12 "2017-12-23T14:43:16Z")

</div>

Yippie, solved it 😄

1. 

- ip6tables -A INPUT -p tcp --dport 443 -j REJECT --reject-with tcp-reset
- ip6tables -A INPUT -p tcp --dport 443 -j REJECT --reject-with tcp-reset

1. edit the IPV4\_ADDRESS and IPV6\_ADDRESS in /etc/pihole/setupVars.conf

- IPV4\_ADDRESS=0.0.0.0
- IPV6\_ADDRESS=0000:0000:0000:0000:0000:0000:0000:0000

see:

> Blockquote see tps://discourse.pi-hole.net/t/pi-hole-unnutzbar-mit-mac-ipad-iphone/4435/13

1. Done! 🎊

:vortex: is realy a nice Christmas present 🎄

All the best  
Monti

---

<div class="post-metadata">

**Author:** ![DL6ER](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dl6er/32/281_2.png) [@DL6ER](https://discourse.pi-hole.net/u/DL6ER)\
**Post date:** [December 23, 2017, 4:06pm UTC](https://discourse.pi-hole.net/t/bahn-de-extreemely-slow/6094/13 "2017-12-23T16:06:37Z")

</div>

Note that setting the values to `0.0.0.0` instead of only installing the proper firewall rules may have unintended side effects as the blocking page and maybe even the Pi-hole dashboard being not reachable any more.
