Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Streaming services blocked

Streaming services such as Netflix and HBO Now are blocked when accessed by apple tv or iOS app. Both Netflix and HBO Now work when access via web browser. Any ideas?

I have only one firewall policy in effect which permits all LAN -> WAN traffic. I have enabled logging on this policy but nothing is showing as blocked. All three types of scanning (ScanFTP, ScanHTTP, Decrypt & Scan HTTPS) on this policy have been disabled. The Web Filter and Application Control settings are set to Allow All.

Thanks.



This thread was automatically locked due to age.
  • I changed the Web Filter and Application Control settings from the default values of "Allow All" to "None" and that fixed the problem. I'll leave it to someone with more network experience to judge whether or not this makes sense.
  • Add me to the list; upgraded to SFOS 15.01.0.376 and TIVO stopped streaming Netflix. Logs indicate Invalid Traffic Rule 0, tried various scan and web filter settings including some HTTP regex bypass rules. The only fix was to create a new rule just for the TIVO and setting all scans to none like Michael. Clearly this a bug since turning everything off defeats the purpose of scanning/filtering. Thanks.
  • Hi,
    Can you please tell me step by step what did you do to fix the problem? I am having the same issue with Netflix. The XG menus are harder to navigate compared to UTM 9.

    Thanks,
    Arun
  • I ended up creating a new user / network rule (at top) under security policy using source: LAN zone, MAC Host entries for Networks (TIVO Mac, Roku MAC, etc), and Any services -- you could use IP addresses in lieu of MAC but didn't want the IP to change unexpectedly. destination: WAN, and Any for networks. Action set to accept with malware scanning disabled and application control / web filter set to None. This has fixed my issue for now.
  • Sounds like the issue that was existent in Sophos UTM

    This was the resolution

    www.astaro.org/.../50903-exception-rule-netflix-streaming.html
  • CyberA... your answer really helped, thanks for explicitly stating the parameters of the rule for firewall newbs like me! I had an issue where CrashPlan quit working as soon as I implemented Sophos XG Home virtual firewall. I could ping the cloud services, other services are working. After I created an explicit firewall rule at the top to allow all HTTPS traffic (I slimmed down to HTTPS instead of "Any") from the 3 computers specifically CrashPlan immediately started working.

    I also have an issue with Xbox 360 and Netflix where it will hit 25% and then halt. I'm going to test this rule for that device as well and see if it solves the issue. Great idea with the MAC addresses as well. The computers above I have set to fixed IP but for other devices it's nice to have the MAC option.
  • Setting webfilter to none for a MAC address turns it off completely for that device. This is not the way we should have to fix the issue. I have turned off the webfilter for now, but I am hoping that a better (more granular) solution comes along. What's the point of the webfilter if you have to completely disable it for a device if you also want to be able to stream video?!
  • I actually tested this and it is a Bug informed to the concerned team and is being looked up on.
  • I and many others that I know that are using the new XG Firewall are having the same problem. I dont understand y this thread has been marked SOLVED, Its not solved. The workaround is to disable "web filter" but in noway should this be considered SOLVED. Please FIX the streaming problem in XG Firewall. UTM9 also suffered from the same problem but with some RegEX entries would could fix it ourselves without totally disabling scanning. The RegEX trick does NOT work in XG Firewall. Have a look at this link for an example of the frustration we are all having with this problem. Its 6 pages of talk about XG Firewall so you will have to dig through it to see the complaints about things like Netflix not working and Y some peaple in our community will NOT be using XG till this is FIXED once and for all.
    homeservershow.com/.../index.php
  • Please push that team hard to fix this. This has been a problem even in Sophos UTM and for some reason all communication to support about it would get closed or resolved when in fact it was not resolved. I don't understand y support does not know about this problem or just does not care. Do none of the support people use mobile devices for streaming from services such as Netflix? Or is there a good reason y Sophos does not want us streaming from services like Netflix? Its got to be one or both because it does NOT get fixed.