This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Netflix, what fix?

Hello all...

I'd like to start by saying that I know that this question has been asked time, and time again. I have searched the forum at length and attempted many of the suggested solutions to the problem.  The problem being:

Why, oh why, can I not get Netflix to work on my Roku 3 behind the UTM?  
(Edit: Slacker Radio is another more popular service that also no longer works now.)

In fact, most streaming apps on the Roku ar no longer able to retrieve content. 

I have tried adding the devices to the skip list - fail

I have tried adding regex to the exceptions list - fail (Most solutions offered were variations of regex forms)

I have disabled WebFilter, IPS, ATD, and created the ANY>ALL>ANY firewall rule t open it wide up. No dice. 


I am hoping that there is someone here that has an answer to this question. I had found a post of about a week ago or so that claimed to have resolved the issue, alas to no avail. 

Some minimal logging I am able to get:

2016:03:08-18:04:08 sophos httpproxy[5491]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="POST" srcip="10.10.3.2" dstip="50.16.209.170" user="" group="" ad_domain="" statuscode="200" cached="0" profile="REF_HttProContaLanNetwo (Roku)" filteraction="REF_HttCffRoku (Roku)" size="5939" request="0xe0c9fe00" url="appboot.netflix.com/.../RKU-42XXX-" referer="localcontrol.netflix.com/.../boot.js" error="" authtime="0" dnstime="30028" cattime="0" avscantime="0" fullreqtime="585294" device="0" auth="0" ua="Gibbon/2015.1.1/2015.1.1: Netflix/2015.1.1 (DEVTYPE=RKU-42XXX-; CERTVER=0)" exceptions="av,auth,content,url,ssl,certcheck,certdate,cache,fileextension,patience" content-type="text/plain"

2016:03:08-18:04:10 sophos httpproxy[5491]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="10.10.3.2" dstip="165.254.34.218" user="" group="" ad_domain="" statuscode="200" cached="0" profile="REF_HttProContaLanNetwo (Roku)" filteraction="REF_HttCffRoku (Roku)" size="17559" request="0xdfea5600" url="cdn-0.nflximg.com/.../netflixSound.ogg" referer="secure.netflix.com/.../darwin.js error="" authtime="0" dnstime="30132" cattime="0" avscantime="0" fullreqtime="77311" device="0" auth="0" ua="Gibbon/2015.1.1/2015.1.1: Netflix/2015.1.1 (DEVTYPE=RKU-42XXX-; CERTVER=0)" exceptions="av,auth,content,url,ssl,certcheck,certdate,cache,fileextension,patience" content-type="application/ogg"
2016:03:08-18:04:10 sophos httpproxy[5491]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="10.10.3.2" dstip="165.254.34.218" user="" group="" ad_domain="" statuscode="200" cached="0" profile="REF_HttProContaLanNetwo (Roku)" filteraction="REF_HttCffRoku (Roku)" size="11316" request="0xe0ca1000" url="cdn-0.nflximg.com/.../tone_22khz.ogg" referer="secure.netflix.com/.../darwin.js error="" authtime="0" dnstime="30184" cattime="0" avscantime="0" fullreqtime="87098" device="0" auth="0" ua="Gibbon/2015.1.1/2015.1.1: Netflix/2015.1.1 (DEVTYPE=RKU-42XXX-; CERTVER=0)" exceptions="av,auth,content,url,ssl,certcheck,certdate,cache,fileextension,patience" content-type="application/ogg"
2016:03:08-18:04:40 sophos httpproxy[5491]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="10.10.3.2" dstip="50.16.209.170" user="" group="" ad_domain="" statuscode="400" cached="0" profile="REF_HttProContaLanNetwo (Roku)" filteraction="REF_HttCffRoku (Roku)" size="313" request="0xdfe88a00" url="appboot.netflix.com/.../" referer="localcontrol.netflix.com/.../error.js error="" authtime="0" dnstime="61" cattime="0" avscantime="0" fullreqtime="43885" device="0" auth="0" ua="Gibbon/2015.1.1/2015.1.1: Netflix/2015.1.1 (DEVTYPE=RKU-42XXX-; CERTVER=0)" exceptions="av,auth,content,url,ssl,certcheck,certdate,cache,fileextension,patience" content-type="application/xml"
2016:03:08-18:04:50 sophos httpproxy[5491]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="10.10.3.2" dstip="173.194.123.115" user="" group="" ad_domain="" statuscode="302" cached="0" profile="REF_HttProContaLanNetwo (Roku)" filteraction="REF_HttCffRoku (Roku)" size="258" request="0xe0c23200" url="http://www.google.com/" referer="localcontrol.netflix.com/.../error.js error="" authtime="0" dnstime="15082" cattime="108" avscantime="0" fullreqtime="74729" device="0" auth="0" ua="Gibbon/2015.1.1/2015.1.1: Netflix/2015.1.1 (DEVTYPE=RKU-42XXX-; CERTVER=0)" exceptions="" category="145" reputation="neutral" categoryname="Search Engines" content-type="text/html" application="google" app-id="182"


This thread was automatically locked due to age.
Parents
  • Hi, Andrew, and welcome to the UTM Community!

    If the Roku had been successfully added to the Skiplist, no such lines would appear in the log. That fact and your other comments  indicate that you might benefit from reviewing .

    Cheers - Bob

  • Hi Bob,

    Thank you for your response. I have seen that potential solution and have attempted to implement it. However, when I add my Rokus to the Skiplist it still will not allow netflix, slacker, and other online streaming services. Youtube works fine... 

    I am at a loss and have put in a separate router for the Roku network. My problem now, I cannot grant the router network access to the internet through the Sophos. My Lan is on 10.10.1.0. I added an IF for the router on 192.168.1.0 which in turn issues DHCP on its WiFi on 10.10.2.0 

    I am unable to get internet through the wifi either. And I do realize that this will present the same networking issue to begin with, but this is ultimately how I want my network set up.

    My Interfaces:

    eth1 = WiFi    192.168.1.99/24 - Router in this IF issues 10.10.2.X/24
    eth4 = WAN  192.168.2.1 (Bell router - No BridgeMode availble)
    eth5 = LAN   10.10.1.0/24

  • "However, when I add my Rokus to the Skiplist it still will not allow netflix, slacker, and other online streaming services." - Did you follow #2 in Rulz?

    Cheers - Bob

  • I will try again.

    Right now I need to resolve my wifi not having LAN or WAN connectivity. 

Reply Children
No Data