Streaming service providers all bock IPs of known data centres; they do this to reduce the use of VPNs. This is part of all streaming service proved standard business operations to mitigate regional content access rights breaches. Look inside your stream providers terms (they are mostly regionalised), there will be key things in there.
Here is a snippet from Netflix Australia’s Terms, note the “personal and non-commercial use only and may not be shared with individuals beyond your household”.
Almost certainly this will be the case if you use one of the well known cloud providers.
We don’t struggle with this issue at all, but then our ASN and IP space is not part of Vultr, DO, GCP, AWS or misused enough to attract attention etc.
If you have enough bandwidth on a single WAN I’d just set up an outbound policy so that traffic for Netflix etc. goes directly to the internet and not via the SFC tunnel.