Remote Access only Fully accessible for about 10 seconds

I will share how I do things.

PLEASE ask further if I’ve missed any points / questions.

From there, maybe we can make everyone else’s work?

  1. Comcast ISP
    – XB8 modem in ‘Bridged’ mode (turns off the LAN router & WiFi)
    – ( XB8 still does the Comcast hidden things but not a factor)

  2. Direct wire from XB8 (2.5G port) → WAN port of PfSense
    – You configure an untrusted port and a trusted port when you install.
    – ISP → Untrusted port


I always work from the modem/router → host and while at the host, test & :grin:

At the pfsense, I create a NAT / Port Forward rule

  1. From: ANY address
  2. From: ANY port
  3. Whose destination: my WAN Address
  4. Whose port: “Other” 31415 → 31415 (this is what we’ll tell Plex to use)
  5. Redirect Target IP: 192.168.0.20 (My server LAN IP)
  6. Redirect Target port: 32400 (Plex’s port)

SAVE the rule,
Enable it

With pfsense rule created.
At your computer -
– If using anyone else’s firewall – You MUST allow 32400/TCP
– I turn machine firewalls OFF. (If they get into my network, I have bigger problems

In Plex:

  1. Remote Access – OFF
  2. Remote Access – ON (let it fail)
  3. Manually add the port - 31415
  4. Retry


Beyond this, I further restrict access

  1. Only known IP addresses (by IP, subnet, or FQDN)
  2. I must also allow Plex to probe the machine – they need permission to do so

Adding this restriction means I have to add another set of rules and aliases.

Unless you’re in a very hostile area. A random port from 14000 → 65535 (except for Plex’s well-known ports) should be good.

I’ve used:
– sqrt(2) - first 5 digits
– sqrt(3) - first 5 digits
– Pi - first 5 digits
– Get the idea ? :wink:

@calebmil

May I have your full DEBUG logs ZIP file please?

There’s definitely something else happening to cause those to fail.

https://forums.plex.tv/uploads/short-url/svJROrzrawSKzNcaoAjhVV9mRTW.zip

I also have a more complete write up of the troubleshooting steps I have taken here:

@calebmil

Thanks for that.

I see two things:

  1. Definitely ‘not reachable’ (reachability test fails – =0)
  2. You’ve got IPv6 enabled on LAN which is in IPV4 mode. Turn that off please
    (Settings - Network - Show Advanced)
Sep 09, 2024 16:09:23.632 [11376] DEBUG - [EventSourceClient/pubsub/45.79.197.109:443] EventSource: Got event [data] '<Message address="XXX.XXX.XXX.XXX" port="14997" asyncIdentifier="43e1ca93-6719-4164-97f8-f306a6183dbe" connectivity="0" command="notifyConnectivity"/>'
Sep 09, 2024 16:09:23.632 [11376] DEBUG - [EventSourceClient/pubsub/45.79.197.109:443] PubSub: Got notified of reachability for async identifier 43e1ca93-6719-4164-97f8-f306a6183dbe: 0 for XXX.XXX.XXX.XXX:14997 (responded in 321 ms)
Sep 09, 2024 16:09:23.632 [11376] DEBUG - [EventSourceClient/pubsub/45.79.197.109:443] MyPlex: reachability check - current mapping state: 'Mapped - Publishing'.
Sep 09, 2024 16:09:23.632 [11376] DEBUG - [EventSourceClient/pubsub/45.79.197.109:443] MyPlex: mapping state set to 'Mapped - Not Published (Not Reachable)'.

@calebmil

Question for you:

From your computer:

when you use Canyouseeme.org, and specify the Plex port, does it respond with Yes/visible?

It does.
Message from Can You See Me with IP x’ed out.
Success: I can see your service on xxx.xxx.xxx.xxx on port (yyyyy )
Your ISP is not blocking port yyyyy

I disabled IP V6 on my network adapter as well as IP v6 support in the Plex Network setting. No change.
Plex Media Server Logs_2024-09-23_11-51-35.zip (4.3 MB)

I was about to ask where your Linux server was … then I saw the tag :man_facepalming: lol

I know Linux very well but haven’t touched a Windows box in 15(?) years.
I had a VM for a while but it’s now long gone.

For you, The browser can use the port…
Do you need to do anything to let an app see a port?

There’s nothing Windows Defender/etc needs to know?

Plex.tv get blacklisted ?

No. I even went so far as to turn off Defender briefly to verify it was not a local firewall problem.

I’ve had this configuration working for years. The problems just started with an update in the last few weeks, two months max. From what I have read on the forums, it sounds like it might be related to SSL certificate issues?

And no black listing either. At least me being able to browse to plex.tv from the server would seem to suggest that …

That was it. Your certificate was stuck in Generating status.
I’d looked right at “GENERATING” but read “GENERATED”

I reset your certificate and waited for it to completed GENERATED status.

Restart PMS, give it an extra few seconds to download and install.

Thank you sir! That took care of my issues.

Excellent. My apologies for being slower than normal.

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.