Forum Discussion

MIYO-KEP's avatar
MIYO-KEP
Icon for Joining the Conversation rankJoining the Conversation
3 months ago

Spotify web unable to play music

Hi,

We are new to Cato. One issue I just discovered is with the SDP client running and connected to Cato cloud, if I try to play something on Spotify via the web browser, I get error "Spotify can't play this right now". I have tried various browsers, incognito, etc. 

When I disable the Cato SDP client, refresh the page, then hit the play button, it works. If I enable SDP client, refresh the page, then hit play, it's broken again with the same error above. 

I can see the Spotify traffic events in Cato CMA. Some events show TCP, TLS and HTTPs. Other events show UDP and QUIC. The action shows 'monitor', so why would this be blocked and prevent  music from playing? 

There may be other apps that are blocked, which we need to make exceptions for, so some advice about troubleshooting this, or making exceptions would be much appreciated. Thanks!

8 Replies

  • yumdarling's avatar
    yumdarling
    Icon for Community Manager rankCommunity Manager

    Hey friends! I did a little internal asking around and the team says: 
    We currently have ‘parked domains’ as a system level category, it’s predefined and might already be in one of your internet firewall rules. We suggest to block this category as part of our best practiceshttps://support.catonetworks.com/hc/en-us/articles/4456963164829-Best-Practices-for-Cyber-Security-and-the-Cato-Cloud

    I hope this helps and let me know if you have any further questions or comments for the team :) 

  • MIYO-KEP's avatar
    MIYO-KEP
    Icon for Joining the Conversation rankJoining the Conversation

    ok, I see. At least my experience is consistent. Thanks for checking. 👍

  • JM's avatar
    JM
    Icon for Staying Involved rankStaying Involved

    That's right - it says "Audio file unavailable" when I press Play. DevTools shows a red block entry for the domain clrtpod.com, and when I select "Open in new tab" on that one I get the below expected prompt page. That's the pain of it - the blocking of web page elements that are loaded in the background is not visible to the end user. I've suggested to Cato that they should develop a browser extension that would popup a suitable alert when this happens, but they are yet to take that idea and run with it.

     

  • JM's avatar
    JM
    Icon for Staying Involved rankStaying Involved

    We block parked domains using the Internet Firewall - not sure what is the default Cato policy. I suspect at least it's set to prompt. The event log will tell you what policy is applied.

  • MIYO-KEP's avatar
    MIYO-KEP
    Icon for Joining the Conversation rankJoining the Conversation

    To add, I also had an issue playing some podcasts on https://www.podchaser.com website too. Again, some URLs such as clrtpod.com and pdrl.fm were categorised as parked. I recategorized and the issue was resolved.

  • MIYO-KEP's avatar
    MIYO-KEP
    Icon for Joining the Conversation rankJoining the Conversation

    JM, thanks! I tested again and it seems this only affects some podcasts on Spotify, not music, and not all podcasts. Taking your advice to use Dev Tools in Chrome, I found a few URL's which were inaccessible. I checked these URLs in Cato > Resources > App Catalog > Domain Lookup, and found they were categorized as 'Parked Domains'. I changed the category to 'media stream', waited a while, and the podcasts can now play fine. Great.

    Although, this left me wondering where in Cato's CMA is there a policy to block 'parked domains'? I couldn't find it.

  • JM's avatar
    JM
    Icon for Staying Involved rankStaying Involved

    Spotify works as expected here, but the best way I've found to troubleshoot such issues is to use Developer Tools in the browser to check for elements that are being blocked while on Cato. Then try to load that particular element by itself and see whether it loads or Cato shows up a prompt etc. I've seen web services blocking certain Cato POPs as well, so might be worth doing a manual switch to a different POP just to rule that out.