I think I just found a fix for this one, you need to install the Symantec intermediate cert in to the HTTPS Inspection Trust CAs area. Once I did that, I stopped getting rejected for Netflix.
Here is Netflix getting rejected:
Even though I told it to allow untrusted certificates in the HTTPS Validation configurations:
I looked through the certificate chain for https://www.netflix.com and there was this Intermediate cert in there:
I went to Symantec and found that certificate (Symantec SSL Certificates Support ) and installed it as a Trusted CA in HTTPS Inspection:
Once I did that, I was no longer getting rejected and this should also allow proper enforcement of Netflix as well. On a block rule I was also able to get the UserCheck page to appear, so HTTPS inspection is working properly now.