# Pfsense and plex not working fully

**URL:** <https://forums.plex.tv/t/pfsense-and-plex-not-working-fully/642509>\
**Category:** Remote Access\
**Tags:** server-linux, networking\
**Created:** [October 12, 2020, 8:48pm UTC](https://forums.plex.tv/t/pfsense-and-plex-not-working-fully/642509 "2020-10-12T20:48:30Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![CaptianAwesome](https://avatars.discourse-cdn.com/v4/letter/c/f19dbf/32.png) [@CaptianAwesome](https://forums.plex.tv/u/CaptianAwesome)\
**Post date:** [October 12, 2020, 8:48pm UTC](https://forums.plex.tv/t/pfsense-and-plex-not-working-fully/642509/1 "2020-10-12T20:48:30Z")

</div>

I’m having a rather hard time with getting my plex server connectable outside my network.  
I’ve put in as much info hoping it points out my error. But by all means let me know what else is needed to help and I"ll pull the info ASAP!  
I have followed the numerous forwarding guides but something just isn’t getting through.  
Yes full reboots of Plex and even PFsense have been done to rule that out.  
I don’t know if the issue is pfsense or plex itself at this point.

ISP’s modem is in bridge mode  
PFsense WAN interface is a public IP from ISP = 68.x.x.x  
pfsense LAN interface is 192.168.1.1 - this is the internet gateway for all devices behind pfsense  
Plex - 192.168.1.42:32400 (I have tried multiple ports including 443 all same result)

I have a NAT port forward for TCP/32400 to 192.168.1.42

- I have other NAT forwards and they are all working - SSH on a none regular port for Ex…
- [https://portchecker.co/](https://portchecker.co/) is shows other forwards open but 32400 not, tried a few different ones to be sure…
- NAT = Pure NAT
- Outboud is set to Automatic

Inside the network all systems can get to the Plex server seemingly without issues.

- tablets/phones/xbox/roku  
but I go outside and it’s via relay.
- In plex settings/Network if I turn off Enable Relay I cannot connect from outside at all.

In a browser if I try [https://68.x.x.x:32400/](https://68.x.x.x:32400/) it will NOT connect  
Neither does [http://68.x.x.x:32400/](http://68.x.x.x:32400/)  
ERR\_CONNECTION\_TIMED\_OUT  
But going to [https://192.168.1.42:32400/](https://192.168.1.42:32400/) works fine(obviously when on my own network)  
Going to app.plex.tv does work, but says - Limited Connection

Plex Version = 1.20.3.3421

- Network IPv6 is not enabled  
Manually specify public port - 32400.  
I click Apply and it nearly always turns green. But I click to another setting screen and it turns to a red !

pfsense version = 2.4.5\_1 (community edition)

- Only package installed is open-vm-tools no others at all and never had the blocklist package even as a test…
- I have tried DNS Rebind Check on and off (currently have it ON)
- IPv6 traffic is blocked right now.
- DNS Forwarder - NOT enabled
- DNS Resolver IS enabled
  - custom options: server: private-domain: “plex.direct”

OS = Ubuntu 20.04 (all updated)

- UFW is disabled - I don’t use it at all but have confirmed it’s status too.

---

<div class="post-metadata">

**Author:** ![CaptianAwesome](https://avatars.discourse-cdn.com/v4/letter/c/f19dbf/32.png) [@CaptianAwesome](https://forums.plex.tv/u/CaptianAwesome)\
**Post date:** [October 12, 2020, 11:31pm UTC](https://forums.plex.tv/t/pfsense-and-plex-not-working-fully/642509/2 "2020-10-12T23:31:08Z")

</div>

Some new info. I spun up another VM(same OS, Ubuntu 20.04) Installed Plex and forwarding works great on it.  
The rule in pfsense I just changed the IP, so pfsense is unlikely the issue here.  
It’s either plex itself  
or  
Ubuntu  
I’m leaning hard to the OS, but have no idea what to check. iptables are not being used at the moment and there’s no OS based firewalls.

---

<div class="post-metadata">

**Author:** ![ChuckPa](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/chuckpa/32/79710_2.png) [@ChuckPa](https://forums.plex.tv/u/ChuckPa)\
**Post date:** [October 13, 2020, 3:56pm UTC](https://forums.plex.tv/t/pfsense-and-plex-not-working-fully/642509/3 "2020-10-13T15:56:03Z")

</div>

It sounds like you do have a misconfigured setting but likely in the pfSense itself.

I have both Ubuntu running stock here with pfSense along with all my other development VMs (VMware Workstation). Remote Access “just works”

DNS rebinding checking will only impact discovery on your local LAN.  
I use the pfSense as the domain’s DNS authority (I use certificated https here FQDN)

 ![Screenshot from 2020-10-13 11-44-56](https://global.discourse-cdn.com/plex/original/3X/f/c/fc4e7bc9296a66f7dc6754eab8c89bd517613118.png)  
 ![Screenshot from 2020-10-13 11-48-37](https://global.discourse-cdn.com/plex/original/3X/5/9/5925ecc5c61195658410718328c5c12c50923c3f.png)

Why do you have `open-vm-tools` installed with pfsense? That’s not the place for it. It serves no purpose there unless your pfSense is itself in a VM?

If true, and the Plex server is on that same host, then you’re going to have a huge complexity issue. It’s best to keep pfsense by itself on a dedicated box.

---

<div class="post-metadata">

**Author:** ![CaptianAwesome](https://avatars.discourse-cdn.com/v4/letter/c/f19dbf/32.png) [@CaptianAwesome](https://forums.plex.tv/u/CaptianAwesome)\
**Post date:** [October 15, 2020, 10:14pm UTC](https://forums.plex.tv/t/pfsense-and-plex-not-working-fully/642509/4 "2020-10-15T22:14:05Z")

</div>

pfsense is running as a VM. I have plans to expand to a HA config for pfsense, 1 being the VM and another being a physical device but just not to that point yet. I want to ensure I have pfsense working properly first.  
I installed plex on another ubuntu instance and it just worked perfectly. I go back to this one and nothing gets though, but I cannot find anything in pfsense that relates back to the “bad” instance…

---

<div class="post-metadata">

**Author:** ![ChuckPa](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/chuckpa/32/79710_2.png) [@ChuckPa](https://forums.plex.tv/u/ChuckPa)\
**Post date:** [October 15, 2020, 10:33pm UTC](https://forums.plex.tv/t/pfsense-and-plex-not-working-fully/642509/5 "2020-10-15T22:33:48Z")

</div>

Is your pfSense the real edge device or is it behind another router?

In my case, I have a modem (the ISP device in RFC-1483 transparent bypass mode).  
This means my pfSense box (dedicated) is the internet gateway device which establishes the LAN and manages all NAT and all other services.

I can’t help but thinking you have double NAT there somewhere.

Go look at the interfaces widget and check the IP  
What I show here is my real WAN IP.

If you see any kind of private address then you have double NAT.  
 ![Screenshot from 2020-10-15 18-31-42](https://global.discourse-cdn.com/plex/original/3X/6/c/6c6f466c3fa7e114741b5594b2de33c57927b8e0.png)

---

<div class="post-metadata">

**Author:** ![CaptianAwesome](https://avatars.discourse-cdn.com/v4/letter/c/f19dbf/32.png) [@CaptianAwesome](https://forums.plex.tv/u/CaptianAwesome)\
**Post date:** [October 15, 2020, 10:41pm UTC](https://forums.plex.tv/t/pfsense-and-plex-not-working-fully/642509/6 "2020-10-15T22:41:55Z")

</div>

pfSense is my real edge device. The only thing ahead of it’s WAN interface is the modem which is in bridge mode.  
My WAN interface has an address of 68.x.x.x  
If the issue was double NAT then I’d be more likely to have issues with the new install, and the old still working typically.  
I’d actually be fine to simply run with the new install of Plex but this new install is on the same VM as my VPN(wireguard as client) and I’m getting nowhere telling Plex to use my actual IP/interface. It keeps wanting to use the wireguard interface.

---

<div class="post-metadata">

**Author:** ![ChuckPa](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/chuckpa/32/79710_2.png) [@ChuckPa](https://forums.plex.tv/u/ChuckPa)\
**Post date:** [October 15, 2020, 10:44pm UTC](https://forums.plex.tv/t/pfsense-and-plex-not-working-fully/642509/7 "2020-10-15T22:44:06Z")

</div>

To recap then.

1. Pfsense is in a VM,
2. Pfsense VM has the only access to the ethernet adapter / virtual circuit which connects to the modem ?

This stuff gets so complicated this way and why I sent for dedicated. all physical - nothing virtual,

> **[Is it feasable to setup PfSense as a VM?](https://forum.level1techs.com/t/is-it-feasable-to-setup-pfsense-as-a-vm/140979/5)**
>
> My hope is to use a pfsense VM as the only VM with physical access to a NIC, then let it manage the internal QEMU network so that a Windows 10 VM will already have filtered output going out the physical NIC. Waiting for a Threadripper system to go on...

That’s about it with what I can do.

---

<div class="post-metadata">

**Author:** ![CaptianAwesome](https://avatars.discourse-cdn.com/v4/letter/c/f19dbf/32.png) [@CaptianAwesome](https://forums.plex.tv/u/CaptianAwesome)\
**Post date:** [October 15, 2020, 10:51pm UTC](https://forums.plex.tv/t/pfsense-and-plex-not-working-fully/642509/8 "2020-10-15T22:51:02Z")

</div>

setup is  
Modem -\> VM Host NIC  
pfsense has this host nic as the WAN interface  
pfsense has a LAN interface -\> everything on my network including other VM’s are part of the virtual switch with the pfsense LAN interface.  
PFsense’s internal IP - 192.168.1.1 is the gateway for everything.

Plex VM - with NAT forward setup is dropping the green checkmark as soon as it appears.  
New VM - I took the forwards from plexVM and just changed them to this VM’s IP. This VM is also running wireguard. I shut wireguard off and all is connecting and happy. I turn wireguard on and now it’s blocked.

I need to either fix what is broken in Plex VM - but I have zero clue what it could be  
or  
Fix New VM so that Plex can bypass wireguard.

---

<div class="post-metadata">

**Author:** ![ChuckPa](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/chuckpa/32/79710_2.png) [@ChuckPa](https://forums.plex.tv/u/ChuckPa)\
**Post date:** [October 15, 2020, 11:11pm UTC](https://forums.plex.tv/t/pfsense-and-plex-not-working-fully/642509/9 "2020-10-15T23:11:57Z")

</div>

May I ask why so complicated?

The VPN, like everyone’s VPN, is a HUGE headache unless you manually write the routing table entries -or- have if fully captured (hardware or software)

Make the VPN VM Fully captive (write the routing table rules) or, as you see, or don’t use it.

By not forcing the WAN IP to be seen as the VPN exit IP, you’ll confused Plex.tv **every** time.

This is the bane of everyone who uses VPNs in this manner.

This is why migrating to the captive pfSense box, which internally creates and manages the VPN, is the better method.

The LAN has no idea it’s in a VPN.

What that , I must exit here.

The configuration you have is a split IP config (part is real WAN and part is VPN exit IP). Until that is resolved, it won’t work right.

---

<div class="post-metadata">

**Author:** ![CaptianAwesome](https://avatars.discourse-cdn.com/v4/letter/c/f19dbf/32.png) [@CaptianAwesome](https://forums.plex.tv/u/CaptianAwesome)\
**Post date:** [October 15, 2020, 11:15pm UTC](https://forums.plex.tv/t/pfsense-and-plex-not-working-fully/642509/10 "2020-10-15T23:15:19Z")

</div>

I hadn’t thought of that. I didn’t want any of my house “regular” network to go through the VPN which is why I didn’t set it up there. However if I simply configure pfsense to have the VPN as a path and route the traffic I want that way vs my “regular” traffic it would be cleaner, and likely easier…

---

<div class="post-metadata">

**Author:** ![ChuckPa](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/chuckpa/32/79710_2.png) [@ChuckPa](https://forums.plex.tv/u/ChuckPa)\
**Post date:** [October 15, 2020, 11:29pm UTC](https://forums.plex.tv/t/pfsense-and-plex-not-working-fully/642509/11 "2020-10-15T23:29:01Z")

</div>

with a VPN, it’s all or nothing here unless you know the destination endpoints _and_ create specific custom routes (again, more route table entries).

This is like the “slightly pregnant” . Either yes or no 🙂

That’s why the ‘fully captive gateway device’

you don’t even realize that your outbound traffic is being forced through the ISP’s gateway. That’s a perfect example of “captive”

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/plex/original/3X/2/a/2acb9765406f63293d357b4ec509ec39aa28f2ad.png) [@system](https://forums.plex.tv/u/system)\
**Post date:** [January 13, 2021, 11:29pm UTC](https://forums.plex.tv/t/pfsense-and-plex-not-working-fully/642509/12 "2021-01-13T23:29:01Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
