Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
amartini
New Contributor

Traffic Shaper on Netflix

Hey guys! I am trying to limit the downloads on the netflix website. I noticed that there is an App category for netflix, but in fact when you start seeing a video on netflix it uses HTTPS.BROWSER instead of NETFLIX.Video App. 

Obviously I can't limit the HTTPS.BROWSER for my users and nether create an address list of all the IPs for netflix.

How can we handle this?

 

Thanks.

3 REPLIES 3
hmtay_FTNT
Staff
Staff

Hello amartini,

 

>>I am trying to limit the downloads on the netflix website. I noticed that there is an App category for netflix, but in fact when you start seeing a video on youtube it uses HTTPS.BROWSER instead of NETFLIX.Video App. 

 

Let's fix one problem at the time instead of both. We can start with the detection. Can you send me a packet capture when you try to watch a Netflix video? For the Netflix_* signatures like Netflix_Video.Access signature, they require deep-inspection. They are meant to provide more granularity. Nevertheless, if you do not enable deep-inspection, the "Netflix" signature should identify all the sessions.

 

>>when you start seeing a video on youtube

 

This is a typo I presume. Do you mean Netflix?

 

HoMing

amartini

Sorry, i typed youtube for no reason, it is netflix!   I edited the post. Thnks.

I am 100% sure that my fortigate understand the netflix video play as HTTPS.Browser, I did the tests.

 

As the network traffic detection, you say that I need to enable one deep-inspection on my "allow-internet-rule" to detect the kind of application it is using? I dont use deep-inspection because it warns me "This SSL profile uses full SSL inspection. End users will likely see certificate warnings unless the certificate is installed in their browser".  Today I am using certificate-inspection.

hmtay_FTNT

Can you send me the packet capture and your configuration in a PM? I would like to take a look at it. If you do not use deep-inspection, that is fine. The Netflix signature will still work with certificate-inspection.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors