> Source: [sk157872](https://support.checkpoint.com/results/sk/sk157872)

# sk157872 - User cannot browse to streaming websites such as Netflix and Hulu when using Check Point's Harmony Connect

| Property | Value |
|----------|-------|
| Solution ID | sk157872 |
| Date Created | 2019-07-09 |
| Last Modified | 2021-03-29 |
| Technical Level | General |

## Symptoms

- Users behind a branch office are unable to browse to video content websites such as Netflix, Hulu and others.

## Cause

Check Point's Harmony Connect uses public cloud infrastructure in order to enforce threat prevention, access control and SSL inspection for its end users with very high SLA and QOS.

The public cloud infrastructure has the side effect where users that browse through Check Point will get an IP of a public cloud data center.

Such IP's are typically blocked by copyright-protected video content providers. Examples to such providers are:

* Youtube (for some of the videos)
* Netflix
* Hulu
* HBO Go
* Vimeo (for some of the videos)

## Solution

Check Point recommends to configure direct Internet access for video streaming services, while routing the remaining destination traffic through its Harmony Connect.

This type of configuration can be achieved at the edge router.

**Router-specific configuration examples:**

Silver Peak
-----------

1. Log into your Silver Peak Orchestrator.
2. Navigate to Business Intent Overlays.
3. You should have at least 2 overlays. At the top, an overlay for video content, followed by an overlay for the GRE tunnel.  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1562678622233/1 overlays1907090636.png)
4. Define the match criteria for the overlay for video content. The value for Match Traffic should be set to a custom access control list (ACL). Click the Edit icon in order to set the ACL.  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1562678622233/2 match overlay1907090637.png)

   * **Match Criteria** should be set to the Application Group **TV_and_Video**
   * **Action** should be **Permit**

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1562678622233/4 criteria1907090638.png)

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1562678622233/5 list1907090638.png)
5. Click **Save** .  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1562678622233/6 outcome1907090639.png)
6. The policy for the overlay representing video content should be a single item - Break Out Locally. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1562678622233/7 traffic settings1907090639.png)

7. Note: You can investigate the matched applications for the application group TV_and_Video by navigating to the Application Groups page, and searching for this group. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1562678622233/10 app group1907090639.png)

8. You can investigate the logics of matching each application in that category by navigating to the Application Definitions page, and searching for a specific application. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1562678622233/11 app definitions1907090640.png)

9. The match criteria for the GRE overlay should be set to Match Everything. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1562678622233/8 match criteria for GRE1907090640.png)

10. The policy for the GRE overlay should be the Check Point service object, followed by Break Out Locally. In case you do not have a Check Point service object, please refer to the [integration guide between Silver Peak and Check Point's Harmony Connect.](https://sc1.checkpoint.com/documents/integrations/SilverPeak/check-point-silver-peak-integration.html)

    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1562678622233/8 policy for GRE1907090641.png)

<br />

**Related documentation:**

* [integration guide between Silver Peak and Check Point's Harmony Connect](https://sc1.checkpoint.com/documents/integrations/SilverPeak/check-point-silver-peak-integration.html)

<br />

<br />

### Examples from additional routing providers are coming soon.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
