This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG Firewall Home Edition Netflix

I installed Sophos XG about 3 weeks back.  Until last Thursday I had no problems with the device.  I haven't had a chance to dive in and tweak it to better protect my home network but that is for a different discussion.  Right now my problem is the inability to use Netflix.  It started Thursday night and I just assumed it was the internet or Netflix having issues so I just went to bed.  Friday it was giving me the same error.  It will login to Netflix (on any of my tv's, xboxes, blu-ray players, ect) with no issues but when you click play it says it can not play this title right now.  If I plug in my cheep Belkin router everything works great.  

Please remember I am new to the sophos interface and am still learning.  Is there a way I can exclude netflix traffic from any sort of filtering??  I usually consider my self pretty good with technology but the way sophos is setup I can't find the correct place to put an exclusion.

Any help is greatly appreciated.



This thread was automatically locked due to age.
Parents Reply Children
  • The v17 instructions are newer and less proven.

    Can you provide a screenshot of all parts of the netflix firewall rule?  Is the firewall rule a higher priority than your other web traffic firewall rules?

    If you go to NetFlix and then look in the Log Viewer for "Web Content" do you see the traffic to netflix?  If you do then your firewall rule is not correctly taking effect.

  •  

    I put the netflix rule at the top, so that it triggered before the general rule.  Web log shows direct hits to IPs rather than domains, I wonder if things are different because I'm in Canada?  I know Netflix has different content for each country, but I'm not sure how their network infrastructure plays out to assist that.  Here's a screenshot of the web log for the Roku device (works if I turn off web filtering, of course):

     

  • I noticed that the /24 shown above (209.148.214.0/24) is owned by my ISP (Rogers, one of the big three in Canada) - I added that IP range to the netflix rule and things are now working.  It appears my ISP is playing a little DNS magic with connections to Netflix.

     

    Thanks Mike for your guidance.

     

  • As far as I know (or suspect), NetFlix co-locates some gear at different ISPs in order to offload traffic to their backbone.  I'm wondering if the ISP fiddles with DNS so that devices accessing NetFlix resolve to "local" gear rather the main NetFlix servers.
     
    Can you check something for me?  I want to know if the DNS resolution by your TV/XBOX/whatever is different than the DNS resolution by your XG.
     
    For example, you have a ADSL modem that is running a DNS server, that resolves up to the DNS by your ISP (Rogers).  Your TV etc use the DNS provided by the ADSL modem, therefore they are getting DNS resolution from Rogers.
    But your XG firewall, are you also resolving to your ADSL modem or to the Roger's DNS server, or do you resolve to Google or OpenDNS or something?
     
    If it turns out that your TV and your XG are resolving to different DNS servers, can you as a test change it so they resolve to the same place.  Remove your extra IP from the FQDN host and see if that allows NetFlix to run now that they resolve to the same thing.
  • Mike,

     

    All my media devices (Roku) are getting DHCP from the XG which is handling the DNS queries by forwarding them to my ISP's DNS servers.  My cable modem is running in gateway mode so should only be passing through to the XG, unless there's something I'm not aware of.

  • I had hoped it was something that could easily be traced to DNS, though it sounds like it is not.  Still, I feel the answer is in there regardless.  Do you mind doing a few more tests, in the hope that we can better understand things and improve the KB, or are you happy just to leave it in its working state?

     

    BTW, this is an interesting related article.  Someone tried to find all the netflix content servers. 233 found, plus a breakdown of how common ISP servers are in each country.

    www.theregister.co.uk/.../