Pfsense PIA VPN and Netflix

Ok, great idea, I just used the search in google like Ryan and Wendell used.

I’m not sure if this helps or not but I’ve suggested it to people before. Make sure you’re using the dns resolver in pfsense rather than the dns forwarder. Make sure dns cache is enabled and set the cache life to the same period (or longer) as the alias look up (it should say on the alias page if I remember).

Because the aliases are resolved periodically you want to make sure that the client and the firewall are both getting the same ip for each domain name so using the dns cache should help with that.

1 Like

I had a great deal of trouble getting my PIA up and running but when I finally started tinkering with DNS it worked. It wasn’t this method but I’m sure dexter won’t lead you wrong, OP.

What worked for you? I personally haven’t tried to get Netflix working through a vpn, just some sites which don’t play nice with it.

I ran PIA through it’s internet DNS servers but used my works openDNS connector for everything else. I lost the configuration when the upgrade bricked my install and I haven’t gotten it working again, mainly because of lack of time. When I get it up again I’ll get that config for you.

1 Like

The only way I’ve gotten a Netflix bypass rule to work consistently is to have not only the Netflix ip addresses, but also the Amazon Web Service server addresses that they use. You can use wireshark to generate a list or download the public AWS address ranges in a json file, convert it into a text file, then import them into pfsense as a new alias. Setup a rule to bypass the Netflix ip’s and a separate one for the AWS addresses. This will also create a bypass for Amazon Video as well. The benefit of splitting them means that the AWS ip’s can be easily updated when they change, just download a new list from Amazon. The Netflix ip’s don’t actually change very often. The drawback is that the AWS list contains about 900 ip’s that are being routed around the VPN and many of them probably have nothing to do with video streaming

ExpressVPN has a server in LA that is setup to allow Netflix streaming. A separate one for Amazon Video and Hulu but their service is more than twice the cost of PIA.

All great ideas, While I was checking which services would be affected, only Netflix took the hit, my hulu Sling and Amazon Prime Video services are all working fine.

I did start the list build for Netflix addresses and must have about 10-15 in the list so far. I had seen the AWS servers in the stream but didn’t add them to the list. Maybe that’s what I’m missing.

The other thing I also noticed, while my gaming only added about 10 ms of latency, my overall speed is way down, didn’t really think about the speed of the connections at the end of the tunnel. Having GFiber its kinda hard to see speeds of 200Mbps or less… Ugh.

If you want to avoid the higher latency for online gaming then you’ll need to setup rules for the ports that the games you play use. Most of the popular games should have the port ranges posted somewhere.

Anything under 100 ms is ok, my normal is 70-80 so 80-90 ms is withing range

Did that during the first part of configuring the router, ty.

That would be cool!

I had trouble creating Netflix rules on Pfsense which I think was down to my ISP (Virgin media UK) having their own Caching servers for Netflix. Tried adding some of them to my Alias but couldn’t work it out.

Thanks for replying here, i had completely forgotten about this. I just got PIA set back up yesterday so ill have to get that part working again this weekend.

I found these “netflix” servers, does anyone have any others?

Not sure if you fully resolved your issue. But a quick Google search turned this up.

I had not seen that list, thank you

Not a problem.
That should fix any issues you have, even if it’s not quite the way you’d care to be routing Netflix itself via VPN.

I tested PIA and some of their IP is working with Netflix. Also, I tried PureVPN, ExpressVPN and VyprVPN, only PureVPN is working with good speed.

We highly appreciate that you share your testing experiences with those vpn’s.
But this topic is allready 9 months old, so i guess that topic starter allready found,
a solution for his issue.

There for i’m going to lock this topic.

Before you decide to create a post please check the date of the the topic.
If you have more questions regarding reviving older topics.

Then please check here: Announcement: Reviving Old Threads Guideline Has Been Added to the FAQ

1 Like