This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Netflix not working despite - Knowledge base is wrong?

I have followed this  https://community.sophos.com/kb/en-us/125061

and still I can't get netflix to work, why? only works when I disable web scanning in the rule number 6



This thread was automatically locked due to age.
  • Hi Michael,

    thank you for the detailed investigation. I just tried a n NSLOOKUP from my mac in Australia and was returned a range of addresses which I have checked a couple and they are on Amazon US. Might be of interest?

     

    Non-authoritative answer:

    Name: netflix.com

    Address: 54.69.239.253

    Name: netflix.com

    Address: 34.213.151.116

    Name: netflix.com

    Address: 52.42.235.31

    Name: netflix.com

    Address: 35.160.112.124

    Name: netflix.com

    Address: 54.70.73.70

    Name: netflix.com

    Address: 52.42.228.237

    Name: netflix.com

    Address: 54.71.111.34

    Name: netflix.com

    Address: 52.32.190.151

    Regards

    Ian

  • We are not going to be mapping out all countries/ISPs content delivery servers.  :)

     

    If anyone is curious about Netflix inner structures:

    https://blog.apnic.net/2018/06/20/netflix-content-distribution-through-open-connect/

    https://www.theregister.co.uk/2016/06/22/boffins_map_netflixs_open_connect_cdn/

  • I understand what you are saying, but without the local addresses netflix will not function? They are not Australian sites, they are US sites. The data costs for any Australian ISP/RSP netflix provider would be horrenderous.

    My XG uses local RSP DNS servers.

    Ian

  • Thank you again, good work. [H]

     

    Here is my result from "show fqdn-host":

    cache-ttl:                 dns-reply-ttl

    idle-timeout:            default

    learn-subdomains:    enable

    IP eviction:              disable

  • Thanks Balmasque,

     

    The settings look correct.  Off the top of my head I don't know the next thing to look at.

    I'm on vacation until the new year, and will look at this again then - if you are willing to help investigate.

  • OK, i wish you a nice vacation. Next year i can help to investigate. [Y]

  • Hi TheBalmasque
     
    Can you let me know what device you are connecting through?  eg roku TV, ipad.
     
    Can we confirm that your configuration is correct when using the FQDN Host method?  You should have a high-level rule that has a destination network of Netflix.  Can you please provide a screenshot of the list of firewall rules and the full details of the netflix rule.
     
    Attempt to use Netflix (ideally quit Netflix, start NetFlix, log in, attempt to play a video)
    Go to Hosts and Services, FQDN host.  Set a name filter for "*.n".  You should see several netflix objects.  Hover over the FQDN, it should say something like "3 subdomains, 24 IP address".  You should be able to click in to see full list.  I don't need the details (yet) but let us at least make sure that it is collecting IPs.
     
    Under the log viewer, Web filter, can you see the blocked netflix traffic?  Can you see the destination IP as part of the URL?
     
    Can you find that IP/URL in any of the FQDN host objects?
     
  • Can you let me know what device you are connecting through? 

     

    Its only a Panasonic TV accessing netflix in my network. (TX-55CXW804)

     

    Can we confirm that your configuration is correct when using the FQDN Host method?  You should have a high-level rule that has a destination network of Netflix.  Can you please provide a screenshot of the list of firewall rules and the full details of the netflix rule.

     

    The netlix rule is my first rule. See screenshot below:

     

    Here are the details about the rule:

     

     

     

    When i hover over the FQDN sometimes i got a list shown, other times it says: "No Subdomains found." Strange behaviour...

     

    I hope i can help you with that. [H]

  • TheBalmasque said:

    When i hover over the FQDN sometimes i got a list shown, other times it says: "No Subdomains found." Strange behaviour...

     

    Can you please explain or describe it more detail?  I feel like we are narrowing in here on the issue.

  • Hi there.

    Sorry, i try to reproduce this but it seems i was seeing it wrong. Sometimes the response is a little bit slow, so i think i saw "No Subdomains found". But it was the other entry. For me *.netlix.com always displays 11 subdomains and 96 IP adresses. And *.nflxso.net 3 subdomains 12 IP adresses.

     

    The other entrys like *.nfxvideo.net, *.nflxext.com and *.nflximg.net displays "No Subdomains found". Is this normal?