Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG Firewall Apple TV+ Connection Issues

Ok, so I decided to give Apple TV+ a try.  I am aware of how finicky Apple products can be, but decided to give it a whirl anyway.  Perhaps I'm beating a dead horse on this.

The first issue was the XG blocking QUIC, once I allowed QUIC, streaming seemed to work fine.  Then things started going off the rails.  I now get intermittent issues where Apple Music and Apple TV+ cannot connect.  Apple TV+ provides the following message "Content Unavailable".  This occurs no matter if I use an iPad, iMac or Android box.

I use Android boxes with the Apple TV+ app installed.

Apple Music and Apple TV+ drop out every 15 or 20 minutes and they remain gone for several minutes before miraculously connecting.  During the Apple down time, the Apple TV+ connection tests pass connecting to the internet but fail with connection to Apple.  I can stream using Disney+ with full 4k HDR10 without a single hiccup at any time and no rule exemptions.  My Speedtest shows absolutely no issues with my fibre line.

I have tried a number of "troubleshooting" steps with disabling one thing or the other.  This became extremely time consuming since the XG takes a very long time to update a firewall rule.  To speed things up, I have created the following rule at the top of my rules list:

  • LAN to WAN
  • Allow any service
  • Allow any source
  • Allow any destination
  • Web Policy = "Allow All"
  • Malware scanning disabled
  • Use web proxy instead of DPI
  • App Control = "Allow All"
  • IPS = "None"

Believe it or not, with the above rule the Apple TV+ and Apple Music still refuse to connect.

At this stage I am at a complete loss as to how to troubleshoot this further.  I cannot see how the XG might be interfering with the connection.  

I should add that I am attempting to troubleshoot this from my iMac by testing the Apple TV+ app on it.

As I finish typing this post, Apple TV+ & Apple Music both came back online.



This thread was automatically locked due to age.
Parents
  • I am giving up on this.  There is nothing that I can seem to do to get Apple TV+ working.  I've had an android box running all day trying to stream a movie through Apple TV+.  It never gets more that 15 or 20 minutes before the stream stops and there are no connections to Apple.  For reference, here are my FW settings:

    The Apple IPv4 network is the 17.0.0.0/8 block of IP addresses.  I added it since there are a number of 17.x.x.x addresses that Apple doesn't get domain names for and would not be caught by the *.apple.com domain.

    Looking at the FW log and filtering results for "log subtype is not Allowed" no packets are logged indicated that all packets are allowed.

    Looking at the SSL/TLS log and filtering results for "Action is not Do not decrypt" nothing appears for any sites other than Sophos.  All other packets are labeled as "Do not decrypt".  I have included a snippet below for the only items appearing in my SSL/TLS logs.  There is nothing for any other website.  They are all for *.sophos.com

  • Hi,

    more questions, have you disabled scanning audio and video in the web settings? Is your Apple rule at the top of your rule list? Does log viewer show the AppleTV using your apple rule?

    Unless you have an IPv6 rule adding the IPv6 addresses to the exception list gives no benefit. 

    Ian

    extra, I have IPv6 rules for my Apple devices and find they prefer to use IPv6 rather than ip4.

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Hello Ian,

    Web -> General Settings -> Advanced Settings -> Scan Audio & Video is Unchecked

    The FW rule is at the top of all the rules.

    The devices trying to use Apple TV+ are using that rule for all the selected *.apple.com, *.iCloud.com and 17.x.x.x domains and IP addresses.

    Best regards.

  • Hi,

    one more test, change the services to any. Then check log viewer web report.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Hi Ian,

    The same result.  Connection to Apple is lost after about 20 minutes.  Nothing unusual in the logs, no dropped FW packets and all SSL/TLS packets are “Do not decrypt”.  I’m not sure if there is an issue with the XG, Apple or something my ISP is doing.

    Thanks for your help.

  • Next, internert speed up and down,  cpu and memory load?

    Are you using wifi or hardware? I gave up using wifi the connections were not reliable.

    ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Internet speed test shows 51Mbps down and 19Mbps up.

    XG CPU load = 27% (doesn't really change much)
    XG RAM used = 50%

    All my devices are connected via ethernet cable.  Only the iPhones and iPads are on WiFi.  WiFi speeds have proven too unpredictable to rely on for streaming although I have a friend who streams Netflix via WiFi here regularly without issue.

    I had connection issues with Apple TV 6+ years ago which could not be resolved by Apple.  They gave me a movie credit at that time that I still haven't been able to use.  I now have Disney+ and AmazonPrime that both work flawlessly.  So there is no real need for me to get Apple TV+ working.

Reply
  • Internet speed test shows 51Mbps down and 19Mbps up.

    XG CPU load = 27% (doesn't really change much)
    XG RAM used = 50%

    All my devices are connected via ethernet cable.  Only the iPhones and iPads are on WiFi.  WiFi speeds have proven too unpredictable to rely on for streaming although I have a friend who streams Netflix via WiFi here regularly without issue.

    I had connection issues with Apple TV 6+ years ago which could not be resolved by Apple.  They gave me a movie credit at that time that I still haven't been able to use.  I now have Disney+ and AmazonPrime that both work flawlessly.  So there is no real need for me to get Apple TV+ working.

Children
No Data