Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfSense - Cannot connect to Netflix and Hulu on Andriod devices / Smart TVs

    Scheduled Pinned Locked Moved General pfSense Questions
    43 Posts 15 Posters 10.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      bcruze
      last edited by

      firewall > rules > lan

      add a static entry for each of the devices.

      edit the gateway of EACH statically created device and change it to gateway/ WAN interface.

      this works for both PIA and nordvpn

      1 Reply Last reply Reply Quote 0
      • C
        CCNewb
        last edited by

        @bcruze:

        firewall > rules > lan

        add a static entry for each of the devices.

        edit the gateway of EACH statically created device and change it to gateway/ WAN interface.

        this works for both PIA and nordvpn

        thanks, but it unfortunately didn't make a difference

        Network: 192.168.100.20/32  (IP address of a Smart TV)
        Gateway: 192.168.2.1 (Gateway of WAN2)
        Interface: <interface is="" correct="">I'm using dual-WANs through a gateway group.</interface>

        1 Reply Last reply Reply Quote 0
        • C
          CCNewb
          last edited by

          I'm also not using a VPN.

          It's just pfSense 2.4.2 basic configuration w/ a gateway group setup for Dual WANs.

          I'm going to erase and install 2.3.5

          1 Reply Last reply Reply Quote 0
          • C
            CCNewb
            last edited by

            pfSense 2.3.5, out of the box, didn't configure anything but 1 WAN and LAN through the initial install prompts.

            Same situation- Netflix, Hulu, Amazon Video all fail to load on the Smart TVs.

            Zero issues with Apple and MSFT products.

            This is really frustrating

            1 Reply Last reply Reply Quote 0
            • R
              Rai80
              last edited by

              IPV6 in play?

              1 Reply Last reply Reply Quote 0
              • C
                CCNewb
                last edited by

                @Rai80:

                IPV6 in play?

                Got it disabled / set to "None" on the WAN / LAN interfaces

                Temporarily setup a Floating Firewall rule to Deny any IPv6 Traffic - source anywhere, destination anywhere– but didn't make a difference.

                Poor Amazon Echo won't connect either :/

                1 Reply Last reply Reply Quote 0
                • M
                  molykule
                  last edited by

                  Hi,

                  Heres what i have done. Please make an alias with all the static assigned IP's of media devices. Create a floating rule for that alias and ope the ports for it. I think i have 80 and 443 and then all the ephemeral ports. You can google the range for ephemeral ports.
                  Please see the attached screen shot of my floating rule for media devices. Also if you have squid, by pass the rule for those ip's.

                  Please let me know if you are still stuck,
                  thanks,
                  molykule

                  Untitled.png
                  Untitled.png_thumb

                  1 Reply Last reply Reply Quote 0
                  • C
                    CCNewb
                    last edited by

                    @molykule:

                    Hi,

                    Heres what i have done. Please make an alias with all the static assigned IP's of media devices. Create a floating rule for that alias and ope the ports for it. I think i have 80 and 443 and then all the ephemeral ports. You can google the range for ephemeral ports.
                    Please see the attached screen shot of my floating rule for media devices. Also if you have squid, by pass the rule for those ip's.

                    Please let me know if you are still stuck,
                    thanks,
                    molykule

                    I copied your floating firewall rule starting w/ 1 Smart TV IP – added Alias for ports 80, 443, and 49152:65535, however the issue still persists.

                    Another weird thing I noticed, the "sign in" button on pfchangs.com doesn't trigger the pop-up; happens on all computers.  Works when I switch to Wifi off ISP modem.

                    For what it's worth, I installed and did the basic config of OpenSense-- same issues there too.

                    Here's my full setup if this helps...

                    WAN 1 -> Time Warner Coax -> Netgear Modem -> Linksys Velop Router -> PCIe Dual Nic Port 1 (WAN1 in)
                    WAN 2 -> ATT Uverse Copper -> ATT Modem/Router Combo -> PCIe Dual Nic Port 2 (WAN2 in)
                    LAN out -> Netgear Gigabit Switch -> Wired Devices / Wifi Controller in Bridged modem (DHCP on wifi controller turned off)

                    Ubuntu 16 Desktop Parent Host
                    1x Onboard NIC (LAN in)
                    1x PCIe NIC (LAN out)
                    1x PCEe Dual Nic ( WAN1 in, WAN2 in)

                    Virtual Box- VM Hosting pFSense 2.4.2
                    Bridged Adapters for WAN1 in (em0) WAN2 in (em1) LAN1 out (em2) - > Promiscuous Mode - Deny All on all adapters

                    WAN1 em0: 192.168.2.x (assigned by DHCP of Linksys Router)
                    WAN2 em1: 192.168.1.x (assigned by DHCP of ATT Modem/Router Combo)
                    LAN em2: 192.168.100.1 (gateway for local network devices / issuing DHCP)

                    DNS: I disable internal DNS server from pfSense.  I have LAN DHCP server set to use a custom DNS IP for devices-- a Raspberry Pi thats running PiHole

                    1 Reply Last reply Reply Quote 0
                    • M
                      mrkool
                      last edited by

                      I ran into lots of issues because of the following

                      1. Pfsense loves intel Nic’s (not your issue just throwing it out there)
                      2. Clear the blacklisted ip addresses
                      3. (do u have snort enabled?) if yes what rules sources Are you using?

                      1 Reply Last reply Reply Quote 0
                      • C
                        CCNewb
                        last edited by

                        @mrkool:

                        I ran into lots of issues because of the following

                        1. Pfsense loves intel Nic’s (not your issue just throwing it out there)
                        2. Clear the blacklisted ip addresses
                        3. (do u have snort enabled?) if yes what rules sources Are you using?

                        Nothing blacklisted.  All NICs are physically Intel except 1, but they're all Intel emulated within Virtualbox.

                        For now, I have the TVs connected to the Linksys Velop Wifi (different than my regular wifi controller) / bypassing pfSense.  On the CODELQ traffic shaper for that WAN, I reduced the speed 12mbits leaving room for the TVs if my main network is saturating the circuits.

                        Not sure what snort is, unless it's enabled and installed by default, I don't have it.

                        It's frustrating to the point where I'd pay someone $50 to fix it.  Any takers :)?

                        YanikY 1 Reply Last reply Reply Quote 0
                        • U
                          usedtolosing
                          last edited by

                          You have to enable IPV6 from lan to wan.

                          I had the same issue. My guess is that it is part of the anti-VPN measures Netflix et Al have put in place

                          T 1 Reply Last reply Reply Quote 0
                          • YanikY
                            Yanik @CCNewb
                            last edited by

                            @ccnewb
                            Hey,
                            Are you using DNS Resolver?

                            GertjanG 1 Reply Last reply Reply Quote 0
                            • GertjanG
                              Gertjan @Yanik
                              last edited by

                              @yanik @usedtolosing : why are you replying against a 4 years old thread ?

                              No "help me" PM's please. Use the forum, the community will thank you.
                              Edit : and where are the logs ??

                              1 Reply Last reply Reply Quote 0
                              • U
                                usedtolosing
                                last edited by

                                @gertjan because I found a solution, and I had a problem.

                                Google still returns search results for old threads.

                                Why are you replying to a 4 year old thread?

                                GertjanG 1 Reply Last reply Reply Quote 0
                                • GertjanG
                                  Gertjan @usedtolosing
                                  last edited by

                                  @usedtolosing said in PfSense - Cannot connect to Netflix and Hulu on Andriod devices / Smart TVs:

                                  Google still returns search results for old threads.

                                  pfSense, dated 4 years ago has close to nothing to do with pfSense today.
                                  Like applying a Windows XP solution on Wiondows 10.
                                  Are you using a pfSense version from 2017 ?

                                  No "help me" PM's please. Use the forum, the community will thank you.
                                  Edit : and where are the logs ??

                                  1 Reply Last reply Reply Quote 0
                                  • T
                                    truetype @usedtolosing
                                    last edited by

                                    @usedtolosing
                                    How did you enable IPv6 from LAN to WAN?
                                    This thread may be old, but it's still an Issue with Chromecast 4th gen and Netflix. Although it works when I make a floating rule to pass all for the Chromecast.

                                    I 1 Reply Last reply Reply Quote 0
                                    • I
                                      incith @truetype
                                      last edited by incith

                                      @truetype said in PfSense - Cannot connect to Netflix and Hulu on Andriod devices / Smart TVs:

                                      @usedtolosing
                                      How did you enable IPv6 from LAN to WAN?
                                      This thread may be old, but it's still an Issue with Chromecast 4th gen and Netflix. Although it works when I make a floating rule to pass all for the Chromecast.

                                      Yup, I am facing this crazy issue tonight.

                                      Netflix will not let my android login. If I switch off of using pfSense DNS then it works immediately every time.

                                      This is so bizarre. There is nothing in the firewall logs. Nothing. Even pcap is useless, it's like it doesn't show any traffic because the client never gets a DNS response for Netflix. So it never tries to connect.

                                      It is 100% something with DNS. Even if I connect to another vlan it's the same problem. I disabled all firewalling, everything, changed firewall to use Google DNS...last resort would be to try disabling caching I guess.

                                      I'm a senior network admin and this problem is driving me crazy.

                                      Edit: enabling DNS forwarding mode fixes the issue. This is definitely some kind of unbound issue....SO weird.

                                      I 1 Reply Last reply Reply Quote 0
                                      • I
                                        incith @incith
                                        last edited by incith

                                        After some further reading this appears to be due to ECS responses - which adds geolocation type data to the DNS query. Unbound seems to be having some problems with that in pfSense.

                                        When googling e.g 'unbound netflix' more information seems to be coming up. Unbound does support ECS but I've no idea how to go about enabling that in pfSense.

                                        Some workarounds are to set forwarding zones for specific hostnames so that it always sends queries for those domains to upstream servers (hence why forwarding mode works immediately). But it gets cumbersome as Netflix has many hostnames.

                                        E.g:

                                        forward-zone: name: "netflix.com"
                                        forward-addr: 8.8.8.8
                                        

                                        From https://www.reddit.com/r/pihole/comments/n5ne6b/pihole_unbound_netflix_issues/

                                        GertjanG johnpozJ 2 Replies Last reply Reply Quote 0
                                        • GertjanG
                                          Gertjan @incith
                                          last edited by

                                          @incith

                                          ebbebd21-9b24-4ef0-bcd8-1e0506fcaab7-image.png

                                          If people /networks that use pfSense as a firewall router had issues using 'netflix.com' then this would be a hot, ongoing issue on this forum, the unbound support forum, etc.
                                          Actually, every FreeBSD user, as FreeBSD uses unbound by default, would face the issue.
                                          And more : Netflix itself is one of FreeBSD's biggest FreeBSD users .....

                                          So, I say it upfront : sorry for not being able to help, but : what did you do to not making it work ?
                                          It's not hard to create a default pfSrnse installation : after install, connect the WAN.
                                          LAN : same thing - don't use any VLAN stuff... keep the one and only default LAN firewall rule.
                                          Just change the password.
                                          Do not add or change anything related to DNS, as pfSense uses unbound, a solver, so nothing (like zero) is needed to make DNS work.

                                          netflix works ....
                                          Now, get your setup back to what it is now .... netflix doesn't work.

                                          You've found the issue ;)

                                          No "help me" PM's please. Use the forum, the community will thank you.
                                          Edit : and where are the logs ??

                                          1 Reply Last reply Reply Quote 0
                                          • stephenw10S
                                            stephenw10 Netgate Administrator
                                            last edited by

                                            So this is not an IPv6 specific issue?

                                            I've never seen an issue logging into Neflix with an Android based smart TV behind pfSense here. It could be regional I guess.

                                            I provelsP 2 Replies Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.