Remote access no longer working

Hello. My remote access is no longer working as of about 15 days ago with no network or PMS changes. Updated to latest PMS and did not solve. No changes to my wifi/router, but rebooted as well and port forward is still present (upnp is not enabled, but port forward has been working for years). Looking at the forum, seems others are having a the same issue and my certificate may have expired. I am NOT using a custom certificate. I do see an ‘DEBUG - CERT: incomplete TLS handshake from 192.168.1.x:52080: sslv3 alert certificate unknown (SSL routines)’ in the log when I do a retry of the remote access connection. Attached a redacted log as well.

If nothing in my logs seems like my cert expired, then I think my ISP may have decided to enable CG-NAT per your troubleshooting guide (and I might be out of luck), however the public IP (what is my ip) that is showing has not changed in a couple of years as my opendns content settings still work fine.

Thanks
Plex Media Server_redacted.log (28.2 KB)

  1. For future reference –

ALL RFC-1918 addresses are NON-ROUTABLE; meaning they do not need to be redacted. The Internet does not allow those addresses outside your modem-router nor do the Internet routers pass them even if the address did get out.

  1. Your certificate is OK. It was generated in May and is valid through end of this month (when it will renew)

  2. This looks like someone using an old plex.direct address (which expired long ago)

Something did change. – perhaps on your side because I do see your server Published at your WAN address (about 2 hours before my reply here)

Since you previously posted 6 hours ago, Have you been able to resolve it?

Just rechecked…it is still not working. The logs I provided were from a week ago when I first made an inquiry via DM, then was asked to repost here. I have attached updated logs just now when performing a retry again. What do you mean by old plex.direct? Again, no changes on my router or PMS server - just stopped working. Updated to slightly newer version just in case, rebooted, and rebooted router - no difference.
When retrying the remote access on the console, it says 'fully accessible outside your network, then after about 3-5 seconds, it goes back to 'not available outside your network. If you need more logs I can send, just trying to capture the retry effort by the server.

PMS version 1.32.4.7195

Plex Media Server_071723_redacted.log (29.2 KB)

Please turn off Remote Access for an hour.

Plex.tv is telling your machine to stop trying and throttling it (ignoring)

Jul 17, 2023 21:54:31.480 [140152251947832] DEBUG - [Req#195bc] MyPlex: Sending Server Info to myPlex (user=xusernamex@gmail.com, ip=24.101.2xx.1xx, port=0)
Jul 17, 2023 21:54:31.480 [140152251947832] DEBUG - [Req#195bc/HCl#11ebe] HTTP requesting POST https://plex.tv/servers.xml?auth_token=xxxxxxxxxxxxxxxxxxxx
Jul 17, 2023 21:54:31.821 [140152569948984] DEBUG - [HttpClient/HCl#11ebe] HTTP/2.0 (0.3s) 422 response from POST https://plex.tv/servers.xml?auth_token=xxxxxxxxxxxxxxxxxxxx (reused)
Jul 17, 2023 21:54:31.821 [140152251947832] DEBUG - [Req#195bc] MyPlex: Published Mapping State response was 422
Jul 17, 2023 21:54:31.821 [140152251947832] DEBUG - [Req#195bc] MyPlex: Got response for 1ecebaa6ffd6763d713c6c4e8de3403565bceb08 ~ registered :0

This still bothers me.

Jul 17, 2023 21:55:11.954 [140152609434424] DEBUG - CERT: incomplete TLS handshake from 192.168.1.21:61369: sslv3 alert certificate unknown (SSL routines)
Jul 17, 2023 21:55:11.954 [140152609434424] DEBUG - CERT: incomplete TLS handshake from 192.168.1.21:61370: sslv3 alert certificate unknown (SSL routines)

I don’t know if you’re using your own certificate (which PMS isn’t recognizing) or it’s something else.

Would you like to try a certificate reset ?
If you have your own certificate then I’d make certain it meets the new SSL v3.0.0 specification (which PMS requires as of 1.32.0)

I just disabled remote access and will leave it disabled until this evening (more than 8 hours). I am not using a custom cert, so willing to try a cert reset.

Thanks.

I just reenabled remote access, same issue. Lets try cert reset.

Certificate reset & generated.

If it’s not working then it is definitely on your end.

Check the port numbers and each forwarding rules then also check the Linux firewall rule(s) if you have them enabled.

The host must allow 32400/TCP at the host.
External WAN port (TCP) is whatever port number you decide.
(Did you manually specify one or use UPNP – Is UPNP working?)

Hi @ChuckPa, my remote connections stopped working, is it possible i need a cert reset to?
My server has been stable for several years.

@MackanMask

I can’t tell what’s happening; You turned off DEBUG logging.

Remote Access issues are 99% not a server certificate.

It’s been common experience for Modem/Router updates (clears/disabled port forwarding / UPNP). OS firewalls reset open ports (Synology DSM frequently does this)

Your best tool is canyouseeme.org.
From there, you walk through to confirm the port is open all the way through.

When confirmed. DEBUG server logs can take us the last step.

1 Like

Thanks @ChuckPa, remembered that i updated my firewall a week ago, must be that.

Edit: was my firewall, problem solved, thanks for the help.

1 Like

It is still not working. Triple checked the port forwards. My ISP must have changed something or enabled CG NAT. Thanks.

Log into your modem.

Look at it’s WAN IP address.

It should match “Whatsmyip” address.

Contacted my ISP. They removed the CG-NAT. It is now working! Thanks ChuckPa.

1 Like

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.