I have followed this https://community.sophos.com/kb/en-us/125061
and still I can't get netflix to work, why? only works when I disable web scanning in the rule number 6
This thread was automatically locked due to age.
I have followed this https://community.sophos.com/kb/en-us/125061
and still I can't get netflix to work, why? only works when I disable web scanning in the rule number 6
Hi Michael,
thank you for the detailed investigation. I just tried a n NSLOOKUP from my mac in Australia and was returned a range of addresses which I have checked a couple and they are on Amazon US. Might be of interest?
Non-authoritative answer:
Name: netflix.com
Address: 54.69.239.253
Name: netflix.com
Address: 34.213.151.116
Name: netflix.com
Address: 52.42.235.31
Name: netflix.com
Address: 35.160.112.124
Name: netflix.com
Address: 54.70.73.70
Name: netflix.com
Address: 52.42.228.237
Name: netflix.com
Address: 54.71.111.34
Name: netflix.com
Address: 52.32.190.151
Regards
Ian
We are not going to be mapping out all countries/ISPs content delivery servers. :)
If anyone is curious about Netflix inner structures:
https://blog.apnic.net/2018/06/20/netflix-content-distribution-through-open-connect/
https://www.theregister.co.uk/2016/06/22/boffins_map_netflixs_open_connect_cdn/
I understand what you are saying, but without the local addresses netflix will not function? They are not Australian sites, they are US sites. The data costs for any Australian ISP/RSP netflix provider would be horrenderous.
My XG uses local RSP DNS servers.
Ian
Thank you again, good work. [H]
Here is my result from "show fqdn-host":
cache-ttl: dns-reply-ttl
idle-timeout: default
learn-subdomains: enable
IP eviction: disable
Thanks Balmasque,
The settings look correct. Off the top of my head I don't know the next thing to look at.
I'm on vacation until the new year, and will look at this again then - if you are willing to help investigate.
OK, i wish you a nice vacation. Next year i can help to investigate. [Y]
Can you let me know what device you are connecting through?
Its only a Panasonic TV accessing netflix in my network. (TX-55CXW804)
Can we confirm that your configuration is correct when using the FQDN Host method? You should have a high-level rule that has a destination network of Netflix. Can you please provide a screenshot of the list of firewall rules and the full details of the netflix rule.
The netlix rule is my first rule. See screenshot below:
Here are the details about the rule:
When i hover over the FQDN sometimes i got a list shown, other times it says: "No Subdomains found." Strange behaviour...
I hope i can help you with that. [H]
TheBalmasque said:When i hover over the FQDN sometimes i got a list shown, other times it says: "No Subdomains found." Strange behaviour...
Can you please explain or describe it more detail? I feel like we are narrowing in here on the issue.
Hi there.
Sorry, i try to reproduce this but it seems i was seeing it wrong. Sometimes the response is a little bit slow, so i think i saw "No Subdomains found". But it was the other entry. For me *.netlix.com always displays 11 subdomains and 96 IP adresses. And *.nflxso.net 3 subdomains 12 IP adresses.
The other entrys like *.nfxvideo.net, *.nflxext.com and *.nflximg.net displays "No Subdomains found". Is this normal?