Comcast sandbox network

Comcast's sandbox network specifies a DNS server that responds to all DNS requests with an IP for a Comcast server inside the sandbox.

This server returns a HTTP 403 Not Authorized error for all requests that do not have the string Mozilla in the request's HTTP User-Agent header, although it seems that this is not documented anywhere, and nobody I've spoken to at Comcast about it knows anything about it.

The two theories I have are a) this restricts access to the internal configuration site (presumably) to just a list of supported browsers, or b) this was done as an attempt to repair some of the damage done by the misbehaving DNS server such that programs or devices that function over HTTP might not fetch bad data.