Not Available outside your network stuck/failed Plex certificates

Remote Access flips green briefly, then red.

Network path appears confirmed working:

  • ISP: AT&T Fiber
  • Gateway: BGW620 in IP Passthrough
  • Router: ASUS GT-BE19000AI
  • Router WAN receives a public IPv4 address
  • Port forward: TCP 32400 → Plex server LAN IP:32400
  • From cellular, http://[PUBLIC_IP]:32400/web/index.html loads Plex successfully

Roku clients show the server offline unless Allow Insecure Connections is set to Always.

I tested a completely fresh Plex server identity/database on the same Mac and the issue still happens.

Logs show:
HTTP error requesting GET https://[PUBLIC_IP_AS_DASHES].[REDACTED].plex.direct:32400/identity
SSL certificate problem: unable to get local issuer certificate

Then:
MyPlex: mapping state set to ‘Mapped - Not Published (Not Reachable)’

Can Plex staff check/revoke/reset the plex.direct certificate or secure connection registration for this server/account?

Server Version#:1.43.2.10687

Your cert shows it was reset/refreshed today and it is not stuck.

Since you have AT&T ( i have it too) can you see if their Active Armor Internet security is disabled. Ive had it off forever cuz it used to at least cause issues with remote access. but it has been so long not sure if they lightened their policies.

I actually just switched over to ATT today because I’ve blown up everything else

Erased the macOS thinking it was software related

Replaced my Eero with a new Router

Replaced my Fiber ISP today

Issue still remains

I just checked my ATT Home Manager App and Active Armor is not activated currently

Just to rule out any dns issues, are you using the default dns servers from AT&T? If so, suggest changing them to 8.8.8.8/8.8.4.4 or 1.1.1.1/1.0.0.1 and giving everything a reboot after.

Also, if your Asus has a dns rebind protection setting, either disable it or if there’s an option to add an exception, you can add plex.direct or something similar to rebind-domain-ok=/plex.direct/

Are you running a pihole or anything similar on your network?

Thanks! I actually switched over to 8.8.8.8 and 1.1.1.1 with a reboot no avail. And I did verify that DNS Rebind protection was turned off. No pihole or anything on the network. I was certain it had to have been my Cert as i’ve literally Nuked everything and the issue remains on different ISP different Router and when I made a new test library issue remained.

Can you message me you server logs a few minutes after a restart.

[Mod Edit removed logs. thanks for providing]

Looking at log and your account it looks like you have another active server that is already using 32400 for it’s external port on your network. This would cause a conflict. Each should have it’s own port forward rule. The rules need to use 32400 for the internal/private port but the external/public needs to be different