I have followed this https://community.sophos.com/kb/en-us/125061
and still I can't get netflix to work, why? only works when I disable web scanning in the rule number 6
This thread was automatically locked due to age.
I have followed this https://community.sophos.com/kb/en-us/125061
and still I can't get netflix to work, why? only works when I disable web scanning in the rule number 6
Seems like your "Netflix" object is not correct. Can you show us the content?
I am not able to stream Netflix as well. I have a new install (SFOS 17.1.3 MR-3) that has only one additional firewall rule beyond the defaults. That is the Netflix rule found in community.sophos.com/.../125061. I am trying to stream thru a Roku. I can select Netflix and enter the app with no problems. When I attempt to select a movie, it issues an error msg telling me to try later. Ditto for all Netflix movies I attempted to watch. My rule looks the same as above.
Nevermind, I have no time to troubleshoot bugs that Sophos doesn't even care.
I have excluded the TV's IPs from any web filtering, since the method described in the KB doesn't work.
At least they should delete or update the Knoledge base article.
I would be glad to help out with this problem as long as the folks from Sophos will assist me over the phone. I am a total noob with XG Firewall, having just loaded the software this week. As soon as I ran into this problem I just returned to Untangle and continued to watch Netflix. I can be available most any time.
I got the same error message here.
Since v17 I use the "netflix" FQDN object. With version 17 to 17.1 it works. But since 17.5 there are sometimes problems.
For 2 days it worked with the firewall rule "netflix". So sometimes it works, sometimes not. Seems to depend on coincidence.
I think there are some new streaming servers not adressed in the netlix FQDN object, so i think the objects needs to be updated. [^o)]
Would be nice to find any reference on changed objects. Maybe you find something on the netflix page? OR in the logviewer?
Would be nice to find any reference on changed objects. Maybe you find something on the netflix page? OR in the logviewer?
I filtered the log using my ROKU IP address and then exported it to a CSV file. When I attempted to insert the CSV file into this post, I received an error. No explanation, just the work ERROR.
Hi,
yesterday i got some time to look in the logviewer. There are several ip-adresses being scanned by the proxy. (Allowed)
So i added a new IP-Host object "Netflix-IPs". Type: IP-List
I put in the following ips: 45.57.74.131, 45.57.78.136,45.57.78.141,45.57.75.172,45.57.74.157,45.57.75.175
Then I put the "Netflix-IP" object in my "Netflix" (same like in the Sophos KB) rule. After that, the movie streaming works. But only for one movie...
For another movie i had to put in some more adresses... Maybe i should try to exclude an ip-range. [:)]
FloSupport Can we get this into the KBA? :)
Hey Community,
Apologies for this inconvenience, and thank you TheBalmasque for sharing your solution.
For context, has anyone tried creating their Netflix exception via the v16 method IP Regex list in the same KBA?
In the meantime, i'll follow up with our team to get the KBA updated.
Thanks,
Thank you for the detailied answer. [:)]
Yes i am running 17.5 with FQDN host method and had some problems, so i created the ranges wich worked for me. But like you mentioned it surely depends on the country you living in.
When i got some problems again i will update this thread. Thank you again for your time. [Y]
By the way: As a paying customer we are still using UTM. For home i'm on the XG, because i think it is the future and will replace the UTM sometime.
Here are all the IP ranges that Netflix owns. This does not include IPs that ISPs may be using as local caches.
This has carefully been converted into RegEx for the exception. Please don't modify these regex, they are specially crafted to meet those IP ranges.
^23\.246\.([0-9]|[1-5][0-9]|6[0-3])\.[0-9]
^37\.77\.(1(8[4-9]|9[0-1]))\.[0-9]
^45\.57\.([0-9]|[1-9][0-9]|1([0-1][0-9]|2[0-7]))\.[0-9]
^64\.120\.(1(2[8-9]|[3-9][0-9])|2([0-4][0-9]|5[0-5]))\.[0-9]
^66\.197\.(1(2[8-9]|[3-9][0-9])|2([0-4][0-9]|5[0-5]))\.[0-9]
^192\.173\.(6[4-9]|[7-9][0-9]|1([0-1][0-9]|2[0-7]))\.[0-9]
^69\.53\.(2(2[4-9]|[3-4][0-9]|5[0-5]))\.[0-9]
^108\.175\.(3[2-9]|4[0-7])\.[0-9]
^185\.2\.(2(2[0-3]))\.[0-9]
^185\.9\.(1(8[8-9]|9[0-1]))\.[0-9]
^198\.38\.(9[6-9]|1([0-1][0-9]|2[0-7]))\.[0-9]
^198\.45\.(4[8-9]|5[0-9]|6[0-3])\.[0-9]
^208\.75\.(7[6-9])\.[0-9]
In order to get Netflix working for you, you added the IP range "45.57.74.100-200" which is in those subset. Someone adventurous could try to convert all the ranges into FQDN hosts. Or if want to use the ranges, it is easier to just use the RegEx exception.
Can you go into the XG Device Console (not an ssh command line) and tell me the results of
show fqdn-host
Hi Michael,
thank you for the detailed investigation. I just tried a n NSLOOKUP from my mac in Australia and was returned a range of addresses which I have checked a couple and they are on Amazon US. Might be of interest?
Non-authoritative answer:
Name: netflix.com
Address: 54.69.239.253
Name: netflix.com
Address: 34.213.151.116
Name: netflix.com
Address: 52.42.235.31
Name: netflix.com
Address: 35.160.112.124
Name: netflix.com
Address: 54.70.73.70
Name: netflix.com
Address: 52.42.228.237
Name: netflix.com
Address: 54.71.111.34
Name: netflix.com
Address: 52.32.190.151
Regards
Ian