Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Streaming Services Blocked

"Reopening" this thread since it is a ongoing issue. As others have already experienced, I'm running into the same streaming issues. Netflix, PluralSite, and other streaming services won't work on AppleTV, Wii, Samsung Smart TVs, Apple iPad, and Apple iPhones but does through a web browser. Also, audio streams won't stream properly (constantly restart) and PlayStation updates won't download properly (get 175% download messages before throwing an error).  Lastly, I cannot login to some banking websites and have difficulties with content downloading on other reputable sites.

So, as others have, I created a profile which filters based off of MAC address and has malware scanning and web scanning is turned off - so essentially everything that you want in a modern security appliance turned off. Most of the systems began to work, but Netflix on the Wii still does not work (streams get to 100% but never start. I also tried the Netflix filters used on the UTM but as other have experience this does not work on the XG).

Also as others have experienced, no useful log files are created as to what it getting blocked, either Malware or web filtering of any type kills any stream (even simple filters such as blocking webmail will kill a stream - seems to be a issue with the scan engine itself and nothing to do with the content.) 

Obviously this is a serious issue that needs to be addressed as I can purchase a $50 firewall from Walmart that will work better than the XG currently is. Don't get me wrong, I'm a Sophos fan, but this has been an ongoing problem for way too long. What's the plan for this to be fixed? My definition of "fixed" is the ability to have malware scanning and web filtering enabled on devices that stream content. It needs to work this way because a large number of devices stream content and disabling malware scanning and/or web filtering is not on option. 

Has anyone else had better luck with streaming content on the XG with security enabled? I'd like to move back to the UTM firewall, however streaming doesn't work that well on that platform either. 



This thread was automatically locked due to age.
  • Thanks for the info. I just checked and turns out I already had the settings the way you suggested, I even changed them to something else and hit apply then changed them back to match your setting hit apply and still can't stream Netflix on Android devices unless I disable HTTP/HTTPS scanning for the device in Policy, Very very frustrating for sure. What do you have your 'File Size Threshold' set to under HTTP/HTTPS Configuration?

  • I could not have said this better myself. It almost seems Sophos thinks Netflix is for 'Kids' and not something that needs to work because Sophos XG is a big boys toy. Come on Sophos, Can we finally get this FIXED? Does nobody at Sophos have an Android/iOS device that uses Netflix or other streaming services to see this stuff does not work? This is just plain crazy 

  • Have you tried giving the devices static IPs via the DHCPv4 static IP option?  Then putting those IP addresses into the bypass scanner?

  • Yes I have and to the point that is the only way to get Netflix working on Androis/iOS devices, That is not a solution.

    Thanks for taking the time.

  • I can confirm Big Ray's results as well. I have the same settings and as long as HTTP malware scanning is enabled Netflix does not work on mobile devices. What seems odd to me, is that before I updated to 1.1 streaming worked pretty well for the most part. I had intermittent issues but streaming worked for most devices. Once I updated to 1.1 streaming halted for all Android and IOS devices. Not sure how this firmware update fixed the streaming issue.

    If someone from Sophos support could provide recommended settings that they used to confirm the firmware update fixed the streaming issue it would be really helpful. Perhaps I just have one setting off somewhere that is causing the streaming problem?

  • Hey Ian, I get where you're coming from.  I think however, when you look at the reports that show 'objectionable' tems coming up because of categories such as 'Job Search, and Google Tools', you'd have to agree a certain corporate mentality here.  I work at a university and understand more than most that these things have legitimate uses in modern corporations, but my point is I don't think this software has entirely caught up with that thinking.  Of course some might call this type of arrangement forward thinking while others might call it equivalent to 90's mentatlity.  Either way a good firewall product should work for both.

  • Hi,

    Netflix stated a few weeks ago that they will block VPN- and proxied clients while accessing their services. Could it be that their most recent apps on various platforms contains something like a proxy detection which stops streaming after a while itself or cannot be handled correctly by the transparent Sophos proxy?

    Cheers, Jack

  • I couldn't agree more. I've just finished installing the XG at a business that uses TV's that stream NOS 24 (the dutch news network 24 hours). 

    Nope! Sophos says no.... When asked if I recognized the problem I said it's probably a small bug.. It's a new product after all...

    Even though I have the exact same problem at home with the UTM......

  • It has been a few months since the last replies. Has there been any progress on this front? I'm running SFOS 15.01.0 MR-3 and Instagram videos will not play from an iPhone. The logs don't show anything being blocked. Audio & Video File Scanning is Disabled. The videos do play from browser on the desktop, though. Any ideas?

  • Now with 16.05 GA I have the Problem too. I have an exception for https scaning for apple.com. Streaming on apple TV an IOS devices run perfect. After Firmware update apple TV can´t no longer Login Itunes Store. The search function of apple Music don´t go anymore.

    When I switch of http scaning all worked fine. When I Switch on http scaning I have the Problems.

     

     

    Dirk