I have followed this https://community.sophos.com/kb/en-us/125061
and still I can't get netflix to work, why? only works when I disable web scanning in the rule number 6
This thread was automatically locked due to age.
I have followed this https://community.sophos.com/kb/en-us/125061
and still I can't get netflix to work, why? only works when I disable web scanning in the rule number 6
I filtered the log using my ROKU IP address and then exported it to a CSV file. When I attempted to insert the CSV file into this post, I received an error. No explanation, just the work ERROR.
Hi,
yesterday i got some time to look in the logviewer. There are several ip-adresses being scanned by the proxy. (Allowed)
So i added a new IP-Host object "Netflix-IPs". Type: IP-List
I put in the following ips: 45.57.74.131, 45.57.78.136,45.57.78.141,45.57.75.172,45.57.74.157,45.57.75.175
Then I put the "Netflix-IP" object in my "Netflix" (same like in the Sophos KB) rule. After that, the movie streaming works. But only for one movie...
For another movie i had to put in some more adresses... Maybe i should try to exclude an ip-range. [:)]
FloSupport Can we get this into the KBA? :)
Hey Community,
Apologies for this inconvenience, and thank you TheBalmasque for sharing your solution.
For context, has anyone tried creating their Netflix exception via the v16 method IP Regex list in the same KBA?
In the meantime, i'll follow up with our team to get the KBA updated.
Thanks,
Thank you for the detailied answer. [:)]
Yes i am running 17.5 with FQDN host method and had some problems, so i created the ranges wich worked for me. But like you mentioned it surely depends on the country you living in.
When i got some problems again i will update this thread. Thank you again for your time. [Y]
By the way: As a paying customer we are still using UTM. For home i'm on the XG, because i think it is the future and will replace the UTM sometime.
Here are all the IP ranges that Netflix owns. This does not include IPs that ISPs may be using as local caches.
This has carefully been converted into RegEx for the exception. Please don't modify these regex, they are specially crafted to meet those IP ranges.
^23\.246\.([0-9]|[1-5][0-9]|6[0-3])\.[0-9]
^37\.77\.(1(8[4-9]|9[0-1]))\.[0-9]
^45\.57\.([0-9]|[1-9][0-9]|1([0-1][0-9]|2[0-7]))\.[0-9]
^64\.120\.(1(2[8-9]|[3-9][0-9])|2([0-4][0-9]|5[0-5]))\.[0-9]
^66\.197\.(1(2[8-9]|[3-9][0-9])|2([0-4][0-9]|5[0-5]))\.[0-9]
^192\.173\.(6[4-9]|[7-9][0-9]|1([0-1][0-9]|2[0-7]))\.[0-9]
^69\.53\.(2(2[4-9]|[3-4][0-9]|5[0-5]))\.[0-9]
^108\.175\.(3[2-9]|4[0-7])\.[0-9]
^185\.2\.(2(2[0-3]))\.[0-9]
^185\.9\.(1(8[8-9]|9[0-1]))\.[0-9]
^198\.38\.(9[6-9]|1([0-1][0-9]|2[0-7]))\.[0-9]
^198\.45\.(4[8-9]|5[0-9]|6[0-3])\.[0-9]
^208\.75\.(7[6-9])\.[0-9]
In order to get Netflix working for you, you added the IP range "45.57.74.100-200" which is in those subset. Someone adventurous could try to convert all the ranges into FQDN hosts. Or if want to use the ranges, it is easier to just use the RegEx exception.
Can you go into the XG Device Console (not an ssh command line) and tell me the results of
show fqdn-host
Hi Michael,
thank you for the detailed investigation. I just tried a n NSLOOKUP from my mac in Australia and was returned a range of addresses which I have checked a couple and they are on Amazon US. Might be of interest?
Non-authoritative answer:
Name: netflix.com
Address: 54.69.239.253
Name: netflix.com
Address: 34.213.151.116
Name: netflix.com
Address: 52.42.235.31
Name: netflix.com
Address: 35.160.112.124
Name: netflix.com
Address: 54.70.73.70
Name: netflix.com
Address: 52.42.228.237
Name: netflix.com
Address: 54.71.111.34
Name: netflix.com
Address: 52.32.190.151
Regards
Ian
Hi Michael,
thank you for the detailed investigation. I just tried a n NSLOOKUP from my mac in Australia and was returned a range of addresses which I have checked a couple and they are on Amazon US. Might be of interest?
Non-authoritative answer:
Name: netflix.com
Address: 54.69.239.253
Name: netflix.com
Address: 34.213.151.116
Name: netflix.com
Address: 52.42.235.31
Name: netflix.com
Address: 35.160.112.124
Name: netflix.com
Address: 54.70.73.70
Name: netflix.com
Address: 52.42.228.237
Name: netflix.com
Address: 54.71.111.34
Name: netflix.com
Address: 52.32.190.151
Regards
Ian
We are not going to be mapping out all countries/ISPs content delivery servers. :)
If anyone is curious about Netflix inner structures:
https://blog.apnic.net/2018/06/20/netflix-content-distribution-through-open-connect/
https://www.theregister.co.uk/2016/06/22/boffins_map_netflixs_open_connect_cdn/
I understand what you are saying, but without the local addresses netflix will not function? They are not Australian sites, they are US sites. The data costs for any Australian ISP/RSP netflix provider would be horrenderous.
My XG uses local RSP DNS servers.
Ian