Whitelisting Plex - a silly prison project

Hi,

I had the stupid idea of introducing plex to our prison system. Our legal team gave it a go (ripping our own DVDs) and now I’m supposed to build a PMS for 45 juveniles. The IT-crowd has asked me to inform myself on the “internet-needs” of plex. They can give the PMS full access to the internet, but the tablets that the juveniles will use work with a whitelist. So I’ll need specific info on what the IT-crowd will need to whitelist so the plex app can connec to the internet, etc so they can watch their TV-shows and movies over LAN via PLEX.

If you need more info, please don’t hesitate to ask.

kind regards,

S.

Don’t worry about it, I work government and we got a law that allows us to show our own dvd’s to our “audience” as long as it’s withing the prison perimeter because they’re treated as a household. Anyway, its not my problem! I’m the one who’s going to build the PMS and thus my questions so I get help with the network.

That’ll be difficult to achieve. Because the Plex cloud infrastructure is hosted in several data centers around the world. Machines (and therefore the IP’s) are shifted dynamically, based on e.g. load.

And there is no way only the pms has internet, while the tablets who have the app only need lan?

No, because user authentication is done via the cloud. The clients need to authenticate themselves, so they need access to the plex cloud infrastructure.

Alright, so you’re 100% sure it will be an impossible task to whitelist plex on the network? That seems like a problem, as they aren’t allowed to use the internet.

Not 100% impossible, but very difficult and requires a lot of research. You can’t just whitelist the whole IP ranges of those data centers, because that would whitelist a lot of other websites and services as well.

Is there a way to talk to PLEX directly about it? All support seems to go via this forum. Seems like my biggest hurdle will be the network and not the server itself. Ugh. (which means it’s totally out of my hands)

No, all support is done in here. Plex won’t change it either. It has long since been requested to do auth locally. [Feature-Request] Built in local authentication server (prevent plex.tv outage)

Wow okay. This totally sucks. Nice thread also, would seems thats exactly what I need. Do you have any idea if there’s alternatives that would work without online connectivity or a simple whitelist (maybe I’m not supposed to ask here, in that case, delete my comment).

Sorry, no.

you might investigate emby or jellyfin, both of which should be able to authenticate internally.

Actually, a firewall with outbound rules can be based on DNS names :wink:

Like PFSense https://docs.netgate.com/pfsense/en/latest/firewall/using-fqdns-in-aliases.html

EDIT:
And expanding here:

If all tablets are on the same IP Net as the Plex Media Server, and running Private Address Space, then put in an outbound rule, that allows access to plex.tv on port 443 for all clients.
Also put in a rule, that allows the PMS server complete access to the internet
( Above to allow it to get posters, metadata etc. )

That way, a client will contact plex.tv to get a list of servers, find your PMS, and since on the same private IP Net, switch to use that.

And this way, I’m sorry I have no networking background, any other tools still do not have internet access? It’s REALLY important that the juveniles are completely restricted internet access.

Interesting thanks.

Thank you, i’ll take a look at both.

Correct, except been able to browse towards https://plex.tv but no other place

I have forwarded your suggestion to the IT crowd here, thanks a bunch!

1 Like

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.