VPN or public address?
If only you and your household watch away from home, the simplest safe option is a VPN: WireGuard or Tailscale (Jellyfin’s documentation has a Tailscale page). The Jellyfin apps on phones and laptops work over a VPN without changes.
You need a public HTTPS address when someone else watches your library, or when a device can’t run a VPN – most smart TV, Roku and Fire TV sticks. That is what the rest of this guide sets up. It needs a public IP address; check you are not behind CGNAT first.
Jellyfin’s ports – and which to forward
| Port | Used for | Forward it? |
|---|---|---|
| 8096/TCP | Web interface and apps, plain HTTP | No – the proxy connects to it on your LAN |
| 8920/TCP | Jellyfin’s own HTTPS, off by default | No |
| 7359/UDP | Finding servers on the local network | Never – it only works locally |
| 443/TCP | Your reverse proxy | Yes |
Forwarding 8096 directly would send your login and everything else unencrypted, and on a .app name browsers won’t even try plain HTTP. Put a proxy in front.
1. Reverse proxy and Known proxies
Set up Caddy or Nginx Proxy Manager as in the HTTPS guide. With Caddy, the whole site block is:
films.yourname.uk.app {
reverse_proxy 192.168.1.30:8096
}In Nginx Proxy Manager, create a proxy host for films.yourname.uk.app to http://192.168.1.30:8096 and tick Websockets Support – Jellyfin uses WebSockets for playback control and live updates.
Then tell Jellyfin about the proxy. Without this, Jellyfin sees every visitor as coming from the proxy’s LAN address, so it treats outside viewers as local and your remote‑access rules don’t apply.
- Open Dashboard → Networking.
- Under Firewall and Proxy Settings, set Known proxies to your proxy’s address, for example
192.168.1.40(or127.0.0.1if the proxy runs on the same machine). - Check LAN networks lists your home range, such as
192.168.1.0/24. Jellyfin uses it to decide who is “local”. - Under Remote Access Settings, make sure Allow remote connections to this server is on.
- Save and restart Jellyfin.
Note
Jellyfin 12 prints a warning in its log if a subnet in the network or proxy settings is invalid. If remote viewers are treated as local after you save, check the log for that warning.
2. Decide who may connect from outside
Each user has their own switch under Dashboard → Users → (user) → Allow remote connections to this server. Turn it off for accounts that only ever watch at home, and consider a separate, non‑administrator account for yourself for everyday viewing away from home.
Jellyfin doesn’t have built‑in two‑factor sign‑in, so use long, unique passwords for every account that can connect remotely, and remove old accounts.
3. Match streaming to your upload speed
When you watch away from home, the video travels over your upload. Many UK part‑fibre (FTTC) lines upload at 10–20 Mbps, while full‑fibre lines often upload at 100 Mbps or more. A 4K remux can need far more than an FTTC line can send.
Set a ceiling under Dashboard → Playback → Streaming → Internet streaming bitrate limit (Mbps). About 70% of your measured upload speed, divided by the number of people who might watch at once, is a sensible starting point. Jellyfin will then transcode down instead of stuttering – which needs a reasonably capable CPU or hardware transcoding.
4. Forward 443 on your router
Forward TCP 443 (and 80, if your proxy uses HTTP‑01 certificates) to the proxy machine: BT, Virgin Media, Sky, TP‑Link, OpenWrt.
5. Keep the name pointing home
Jellyfin has no dynamic DNS feature of its own, so run the updater on whatever is always on: your router (OpenWrt), your NAS (Synology) or the Jellyfin machine itself. On a Linux host, the five‑minute cron job in the start guide updates home.yourname.uk.app using your uk.app DDNS token. Then add a CNAME record films → home.yourname.uk.app in the uk.app DNS settings.
6. Connect the apps
In each Jellyfin app, add a server with the address https://films.yourname.uk.app – no port number, because the proxy listens on the standard HTTPS port. At home, the apps usually find the server themselves on the LAN; away from home they use the name.
Tip
Some Chromecast and Google TV devices ignore your router’s DNS and use Google’s. That is fine for a public name like this one, but it is why local‑only names often fail on those devices.
7. Check it from outside
- Does the name point home? Look up
films.yourname.uk.appwith the DNS lookup and compare the A record with the address on ip.uk.app. After a change, the propagation checker shows which resolvers still have the old one. - Is the port open from the internet? Run the open port checker against port 443. “Open” means your router forwards it and something answers. “Closed” or “timed out” means the forward, the device’s own firewall or CGNAT is in the way.
- Is the certificate right? The SSL checker shows whether the certificate covers the exact name, who issued it and when it expires.
- Is Jellyfin seeing real addresses? Play something over mobile data, then look at Dashboard → Activity. The session should show your phone’s public IP, not the proxy’s LAN address. If it shows the proxy, Known proxies isn’t set correctly.
- Test from outside for real. Turn Wi‑Fi off on your phone and open the address over mobile data. Testing from inside your own network can give misleading results.
If it doesn’t work
- Apps connect, but playback never starts – usually WebSockets or a proxy timeout. Check the WebSockets option, and raise the proxy’s read timeout if you use plain Nginx.
- Buffering on every film – your upload can’t keep up; lower the internet streaming bitrate limit.
- Works in a browser but not in one TV app – make sure you entered the address with
https://; some apps assume plain HTTP when no scheme is given. - Port closed – check double NAT and CGNAT.