Enabling Remote Access without leaving port wide open

I apologize if I’ve miscategorized this post. It’s my first, and I’m not wholly familiar with the forum here.

Gents, I’ve got a Sophos box that serves as firewall/gateway to my home network. When setting up remote access (not via vpn into home network, obviously - my box isn’t capable of many streams like this), I notice that Plex talks to an AWS-based service periodically. I do not really want to leave the port wide open, and would like to whitelist just the ips from which the AWS communication happens. It might be totally dynamic, and impossible.

If anyone has any other work around that doesn’t leave the port wide open, I’d be glad and grateful to hear it.

Hardware setup:

Sophos box (gateway, firewall)
dual Xeon SAN, FreeNAS

sounds like a question for the sophos community (https://community.sophos.com/)

shouldn’t be difficult…

Yessir. I know how to use Sophos. I probably was not very clear. What I need are the IP’s that Plex uses, so that I can whitelist them instead of leaving the port wide open. I can’t tell if they’re completely dynamic or if there are just a few. I think it’s a matter that a Plex employee might have insight into. Or someone else that might have done the same thing.

This, sadly

Thanks for that. That is unfortunate.

Don’t know anything about Sophos, but my guess is that it wouldn’t be impossible to get the current AWS iprange automatically and only allow connections to/from them on a port. Maybe a python or bash script or something? Have a look here: https://docs.aws.amazon.com/general/latest/gr/aws-ip-ranges.html

Ok then . Good luck!

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.