Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG Firewall Apple TV+ Connection Issues

Ok, so I decided to give Apple TV+ a try.  I am aware of how finicky Apple products can be, but decided to give it a whirl anyway.  Perhaps I'm beating a dead horse on this.

The first issue was the XG blocking QUIC, once I allowed QUIC, streaming seemed to work fine.  Then things started going off the rails.  I now get intermittent issues where Apple Music and Apple TV+ cannot connect.  Apple TV+ provides the following message "Content Unavailable".  This occurs no matter if I use an iPad, iMac or Android box.

I use Android boxes with the Apple TV+ app installed.

Apple Music and Apple TV+ drop out every 15 or 20 minutes and they remain gone for several minutes before miraculously connecting.  During the Apple down time, the Apple TV+ connection tests pass connecting to the internet but fail with connection to Apple.  I can stream using Disney+ with full 4k HDR10 without a single hiccup at any time and no rule exemptions.  My Speedtest shows absolutely no issues with my fibre line.

I have tried a number of "troubleshooting" steps with disabling one thing or the other.  This became extremely time consuming since the XG takes a very long time to update a firewall rule.  To speed things up, I have created the following rule at the top of my rules list:

  • LAN to WAN
  • Allow any service
  • Allow any source
  • Allow any destination
  • Web Policy = "Allow All"
  • Malware scanning disabled
  • Use web proxy instead of DPI
  • App Control = "Allow All"
  • IPS = "None"

Believe it or not, with the above rule the Apple TV+ and Apple Music still refuse to connect.

At this stage I am at a complete loss as to how to troubleshoot this further.  I cannot see how the XG might be interfering with the connection.  

I should add that I am attempting to troubleshoot this from my iMac by testing the Apple TV+ app on it.

As I finish typing this post, Apple TV+ & Apple Music both came back online.



This thread was automatically locked due to age.
Parents Reply Children
  • Thank you for the response Vivek.

    Yes, I used those two Apple pages to create my initial firewall rule.  To do that, I created a new IPv4 address block of 17.0.0.0/8 (this block is owned and used by Apple for their services) and created a rule at the top of the ruleset with the ports from the Apple pages you listed.  In addition, I had all IPS, etc turned off.  The issue still persisted after that.

    While I have every port & service from the Apple Enterprise guide in my rule, I don't have every rule from the TCP & UDP guide since I am not using things like "Apple Remote Desktop".  I have the port ranges for Push Notifications and Web Services listed

    As a last resort, I created a test rule at the top allowing all from Lan to Wan on all ports with no filtering whatsoever.  That rule didn't work either.

    It appears that *.apple.com is already listed as a default exemption in the Web filtering section.  In addition I don't have Web filtering turned on.

    I am beginning to wonder if it is a server issue with Apple as it appears the issue is unrelated to the XG unless there is a setting somewhere that I am completely missing.

  • Interesting, lastly you can also try "Bypass a specific firewall rule for Application Classification and ATP." 
    Even after this if the issue persist then you might be correct it may be at the server related or at the ISP related issue !

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.