PfSense - Cannot connect to Netflix and Hulu on Andriod devices / Smart TVs
-
Hi,
Heres what i have done. Please make an alias with all the static assigned IP's of media devices. Create a floating rule for that alias and ope the ports for it. I think i have 80 and 443 and then all the ephemeral ports. You can google the range for ephemeral ports.
Please see the attached screen shot of my floating rule for media devices. Also if you have squid, by pass the rule for those ip's.Please let me know if you are still stuck,
thanks,
molykule
-
Hi,
Heres what i have done. Please make an alias with all the static assigned IP's of media devices. Create a floating rule for that alias and ope the ports for it. I think i have 80 and 443 and then all the ephemeral ports. You can google the range for ephemeral ports.
Please see the attached screen shot of my floating rule for media devices. Also if you have squid, by pass the rule for those ip's.Please let me know if you are still stuck,
thanks,
molykuleI copied your floating firewall rule starting w/ 1 Smart TV IP – added Alias for ports 80, 443, and 49152:65535, however the issue still persists.
Another weird thing I noticed, the "sign in" button on pfchangs.com doesn't trigger the pop-up; happens on all computers. Works when I switch to Wifi off ISP modem.
For what it's worth, I installed and did the basic config of OpenSense-- same issues there too.
Here's my full setup if this helps...
WAN 1 -> Time Warner Coax -> Netgear Modem -> Linksys Velop Router -> PCIe Dual Nic Port 1 (WAN1 in)
WAN 2 -> ATT Uverse Copper -> ATT Modem/Router Combo -> PCIe Dual Nic Port 2 (WAN2 in)
LAN out -> Netgear Gigabit Switch -> Wired Devices / Wifi Controller in Bridged modem (DHCP on wifi controller turned off)Ubuntu 16 Desktop Parent Host
1x Onboard NIC (LAN in)
1x PCIe NIC (LAN out)
1x PCEe Dual Nic ( WAN1 in, WAN2 in)Virtual Box- VM Hosting pFSense 2.4.2
Bridged Adapters for WAN1 in (em0) WAN2 in (em1) LAN1 out (em2) - > Promiscuous Mode - Deny All on all adaptersWAN1 em0: 192.168.2.x (assigned by DHCP of Linksys Router)
WAN2 em1: 192.168.1.x (assigned by DHCP of ATT Modem/Router Combo)
LAN em2: 192.168.100.1 (gateway for local network devices / issuing DHCP)DNS: I disable internal DNS server from pfSense. I have LAN DHCP server set to use a custom DNS IP for devices-- a Raspberry Pi thats running PiHole
-
I ran into lots of issues because of the following
1. Pfsense loves intel Nic’s (not your issue just throwing it out there)
2. Clear the blacklisted ip addresses
3. (do u have snort enabled?) if yes what rules sources Are you using? -
I ran into lots of issues because of the following
1. Pfsense loves intel Nic’s (not your issue just throwing it out there)
2. Clear the blacklisted ip addresses
3. (do u have snort enabled?) if yes what rules sources Are you using?Nothing blacklisted. All NICs are physically Intel except 1, but they're all Intel emulated within Virtualbox.
For now, I have the TVs connected to the Linksys Velop Wifi (different than my regular wifi controller) / bypassing pfSense. On the CODELQ traffic shaper for that WAN, I reduced the speed 12mbits leaving room for the TVs if my main network is saturating the circuits.
Not sure what snort is, unless it's enabled and installed by default, I don't have it.
It's frustrating to the point where I'd pay someone $50 to fix it. Any takers :)?
-
You have to enable IPV6 from lan to wan.
I had the same issue. My guess is that it is part of the anti-VPN measures Netflix et Al have put in place
-
@ccnewb
Hey,
Are you using DNS Resolver? -
@yanik @usedtolosing : why are you replying against a 4 years old thread ?
-
@gertjan because I found a solution, and I had a problem.
Google still returns search results for old threads.
Why are you replying to a 4 year old thread?
-
@usedtolosing said in PfSense - Cannot connect to Netflix and Hulu on Andriod devices / Smart TVs:
Google still returns search results for old threads.
pfSense, dated 4 years ago has close to nothing to do with pfSense today.
Like applying a Windows XP solution on Wiondows 10.
Are you using a pfSense version from 2017 ? -
@usedtolosing
How did you enable IPv6 from LAN to WAN?
This thread may be old, but it's still an Issue with Chromecast 4th gen and Netflix. Although it works when I make a floating rule to pass all for the Chromecast. -
@truetype said in PfSense - Cannot connect to Netflix and Hulu on Andriod devices / Smart TVs:
@usedtolosing
How did you enable IPv6 from LAN to WAN?
This thread may be old, but it's still an Issue with Chromecast 4th gen and Netflix. Although it works when I make a floating rule to pass all for the Chromecast.Yup, I am facing this crazy issue tonight.
Netflix will not let my android login. If I switch off of using pfSense DNS then it works immediately every time.
This is so bizarre. There is nothing in the firewall logs. Nothing. Even pcap is useless, it's like it doesn't show any traffic because the client never gets a DNS response for Netflix. So it never tries to connect.
It is 100% something with DNS. Even if I connect to another vlan it's the same problem. I disabled all firewalling, everything, changed firewall to use Google DNS...last resort would be to try disabling caching I guess.
I'm a senior network admin and this problem is driving me crazy.
Edit: enabling DNS forwarding mode fixes the issue. This is definitely some kind of unbound issue....SO weird.
-
After some further reading this appears to be due to ECS responses - which adds geolocation type data to the DNS query. Unbound seems to be having some problems with that in pfSense.
When googling e.g 'unbound netflix' more information seems to be coming up. Unbound does support ECS but I've no idea how to go about enabling that in pfSense.
Some workarounds are to set forwarding zones for specific hostnames so that it always sends queries for those domains to upstream servers (hence why forwarding mode works immediately). But it gets cumbersome as Netflix has many hostnames.
E.g:
forward-zone: name: "netflix.com" forward-addr: 8.8.8.8
From https://www.reddit.com/r/pihole/comments/n5ne6b/pihole_unbound_netflix_issues/
-
If people /networks that use pfSense as a firewall router had issues using 'netflix.com' then this would be a hot, ongoing issue on this forum, the unbound support forum, etc.
Actually, every FreeBSD user, as FreeBSD uses unbound by default, would face the issue.
And more : Netflix itself is one of FreeBSD's biggest FreeBSD users .....So, I say it upfront : sorry for not being able to help, but : what did you do to not making it work ?
It's not hard to create a default pfSrnse installation : after install, connect the WAN.
LAN : same thing - don't use any VLAN stuff... keep the one and only default LAN firewall rule.
Just change the password.
Do not add or change anything related to DNS, as pfSense uses unbound, a solver, so nothing (like zero) is needed to make DNS work.netflix works ....
Now, get your setup back to what it is now .... netflix doesn't work.You've found the issue ;)
-
So this is not an IPv6 specific issue?
I've never seen an issue logging into Neflix with an Android based smart TV behind pfSense here. It could be regional I guess.
-
@stephenw10 I don't have a Chromecast, specifically this seems to be android phones.
As to why just android phones .. I don't know.
Definitely a DNS thing and not an ipv6 thing.
-
@incith Only android devices I have is a tablet, and firetv stick thing - I just checked both - and no issues accessing netflix. While I have ipv6 via a HE tunnel, the network my firetv and tablet are on don't have Ipv6 enabled.
-
@stephenw10 said in PfSense - Cannot connect to Netflix and Hulu on Andriod devices / Smart TVs:
It could be regional I guess.
I have READ that they are not VPN friendly. Carry on.
And greetings from The Future! -
@johnpoz For me it was specifically logging in. It worked fine until I logged out, then the sign on screen would not come back on first launch (clear data on app).
I also noticed the Netflix app aggressively trying to use 8.8.8.8 and 8.8.4.4 but I had external DNS blocked.
Unblocking those did not resolve the issue either.
Also was happening on wife's phone. I had full dnssec enabled, not sure if that matters.On my phone, specifying public DNS servers would immediately present the login page again. But no matter what I did on pfSense it would never work.
Occasionally, one time, out of dozens of attempts if would load the login screen - but only once. Second attempt back to nothing. It's like every now and then after flushing the cache I'd get the very first DNS response that perhaps has ecs data. I had dnssec enabled etc etc, and tls DNS. Even disabling all of that didn't work.
Disabled pfblocker, suricata, arpwatch, etc. Nothing worked. Nothing in the logs at all (just the 8.8.8.8 being blocked originally - and I was like "oh this will be an easy fix...I'll just allow Google DNS." Nope.)
Honestly, this is slightly out of my realm but I am 100% convinced it is DNS related.
-
Mmm, FireTV and GoogleTV (or whatever they were calling it) are both Android based and I'd expect to hit something like this.
It's possible they use a different (older?) version of the Netflix app which doesn't include this 'feature' I guess.
-
@incith said in PfSense - Cannot connect to Netflix and Hulu on Andriod devices / Smart TVs:
due to ECS responses - which adds geolocation type data to the DNS query. Unbound seems to be having some problems with that in pfSense.
The module is not enabled in unbound that is on pfsense AFAIK, and testing points to that being the case.. So for example if I do a query to pfsense to
$ dig TXT whoami.ds.akahelp.net @192.168.9.253 +short "ns" "209.snipped"
This is my IP where the query came from.. but listed as NS since yeah that would be the IP where the query came from when resolving. If I query say 8.8.8.8 I get back
$ dig TXT whoami.ds.akahelp.net @8.8.8.8 +short "ip" "209.snipped" "ecs" "209.snipped/24/24" "ns" "172.253.192.78"
Where the ecs is the /24 my IP is on.. the IP is reported as my public IP, also correct, and the ns is whatever google ns actually did the query to get the record.
Not sure why you think that should cause you not to be able to connect to netflix?