I recently upgraded to the Sophos XG from the Sophos UT firewall because I was bored and it was something to do :)
One thing that I did notice is that the Apple TV would refuse to download apps, or even update them
It would appear that Apple use digicert to provide some level of certificate based encryption first which is blocked by the Sophos XG firewall for reasons unknown.
If you add the following to the exceptions list of the web filter things are working again
^([A-Za-z0-9.-]*\.)?digicert\.com\.?/
I've bypassed everything.
Hope this helps someone who finds themselves in the same boat as I was.
This thread was automatically locked due to age.