I have followed this https://community.sophos.com/kb/en-us/125061
and still I can't get netflix to work, why? only works when I disable web scanning in the rule number 6
This thread was automatically locked due to age.
I have followed this https://community.sophos.com/kb/en-us/125061
and still I can't get netflix to work, why? only works when I disable web scanning in the rule number 6
I would be glad to help out with this problem as long as the folks from Sophos will assist me over the phone. I am a total noob with XG Firewall, having just loaded the software this week. As soon as I ran into this problem I just returned to Untangle and continued to watch Netflix. I can be available most any time.
I got the same error message here.
Since v17 I use the "netflix" FQDN object. With version 17 to 17.1 it works. But since 17.5 there are sometimes problems.
For 2 days it worked with the firewall rule "netflix". So sometimes it works, sometimes not. Seems to depend on coincidence.
I think there are some new streaming servers not adressed in the netlix FQDN object, so i think the objects needs to be updated. [^o)]
Would be nice to find any reference on changed objects. Maybe you find something on the netflix page? OR in the logviewer?
I filtered the log using my ROKU IP address and then exported it to a CSV file. When I attempted to insert the CSV file into this post, I received an error. No explanation, just the work ERROR.
Hi,
yesterday i got some time to look in the logviewer. There are several ip-adresses being scanned by the proxy. (Allowed)
So i added a new IP-Host object "Netflix-IPs". Type: IP-List
I put in the following ips: 45.57.74.131, 45.57.78.136,45.57.78.141,45.57.75.172,45.57.74.157,45.57.75.175
Then I put the "Netflix-IP" object in my "Netflix" (same like in the Sophos KB) rule. After that, the movie streaming works. But only for one movie...
For another movie i had to put in some more adresses... Maybe i should try to exclude an ip-range. [:)]
FloSupport Can we get this into the KBA? :)
Hey Community,
Apologies for this inconvenience, and thank you TheBalmasque for sharing your solution.
For context, has anyone tried creating their Netflix exception via the v16 method IP Regex list in the same KBA?
In the meantime, i'll follow up with our team to get the KBA updated.
Thanks,
Thank you for the detailied answer. [:)]
Yes i am running 17.5 with FQDN host method and had some problems, so i created the ranges wich worked for me. But like you mentioned it surely depends on the country you living in.
When i got some problems again i will update this thread. Thank you again for your time. [Y]
By the way: As a paying customer we are still using UTM. For home i'm on the XG, because i think it is the future and will replace the UTM sometime.
Here are all the IP ranges that Netflix owns. This does not include IPs that ISPs may be using as local caches.
This has carefully been converted into RegEx for the exception. Please don't modify these regex, they are specially crafted to meet those IP ranges.
^23\.246\.([0-9]|[1-5][0-9]|6[0-3])\.[0-9]
^37\.77\.(1(8[4-9]|9[0-1]))\.[0-9]
^45\.57\.([0-9]|[1-9][0-9]|1([0-1][0-9]|2[0-7]))\.[0-9]
^64\.120\.(1(2[8-9]|[3-9][0-9])|2([0-4][0-9]|5[0-5]))\.[0-9]
^66\.197\.(1(2[8-9]|[3-9][0-9])|2([0-4][0-9]|5[0-5]))\.[0-9]
^192\.173\.(6[4-9]|[7-9][0-9]|1([0-1][0-9]|2[0-7]))\.[0-9]
^69\.53\.(2(2[4-9]|[3-4][0-9]|5[0-5]))\.[0-9]
^108\.175\.(3[2-9]|4[0-7])\.[0-9]
^185\.2\.(2(2[0-3]))\.[0-9]
^185\.9\.(1(8[8-9]|9[0-1]))\.[0-9]
^198\.38\.(9[6-9]|1([0-1][0-9]|2[0-7]))\.[0-9]
^198\.45\.(4[8-9]|5[0-9]|6[0-3])\.[0-9]
^208\.75\.(7[6-9])\.[0-9]
In order to get Netflix working for you, you added the IP range "45.57.74.100-200" which is in those subset. Someone adventurous could try to convert all the ranges into FQDN hosts. Or if want to use the ranges, it is easier to just use the RegEx exception.
Can you go into the XG Device Console (not an ssh command line) and tell me the results of
show fqdn-host
Hi Michael,
thank you for the detailed investigation. I just tried a n NSLOOKUP from my mac in Australia and was returned a range of addresses which I have checked a couple and they are on Amazon US. Might be of interest?
Non-authoritative answer:
Name: netflix.com
Address: 54.69.239.253
Name: netflix.com
Address: 34.213.151.116
Name: netflix.com
Address: 52.42.235.31
Name: netflix.com
Address: 35.160.112.124
Name: netflix.com
Address: 54.70.73.70
Name: netflix.com
Address: 52.42.228.237
Name: netflix.com
Address: 54.71.111.34
Name: netflix.com
Address: 52.32.190.151
Regards
Ian
We are not going to be mapping out all countries/ISPs content delivery servers. :)
If anyone is curious about Netflix inner structures:
https://blog.apnic.net/2018/06/20/netflix-content-distribution-through-open-connect/
https://www.theregister.co.uk/2016/06/22/boffins_map_netflixs_open_connect_cdn/
I understand what you are saying, but without the local addresses netflix will not function? They are not Australian sites, they are US sites. The data costs for any Australian ISP/RSP netflix provider would be horrenderous.
My XG uses local RSP DNS servers.
Ian
Thank you again, good work. [H]
Here is my result from "show fqdn-host":
cache-ttl: dns-reply-ttl
idle-timeout: default
learn-subdomains: enable
IP eviction: disable
Thanks Balmasque,
The settings look correct. Off the top of my head I don't know the next thing to look at.
I'm on vacation until the new year, and will look at this again then - if you are willing to help investigate.
OK, i wish you a nice vacation. Next year i can help to investigate. [Y]
Can you let me know what device you are connecting through?
Its only a Panasonic TV accessing netflix in my network. (TX-55CXW804)
Can we confirm that your configuration is correct when using the FQDN Host method? You should have a high-level rule that has a destination network of Netflix. Can you please provide a screenshot of the list of firewall rules and the full details of the netflix rule.
The netlix rule is my first rule. See screenshot below:
Here are the details about the rule:
When i hover over the FQDN sometimes i got a list shown, other times it says: "No Subdomains found." Strange behaviour...
I hope i can help you with that. [H]