Guide

Jellyfin remote access with a reverse proxy and your own name

Jellyfin is fully self‑hosted – there is no relay service – so reaching it from outside is up to you. The Jellyfin team advise against forwarding its port straight to the internet. This guide puts it behind a reverse proxy on https://films.yourname.uk.app instead.

Updated · Checked against Jellyfin 12.1 · 5 min read

Jellyfin ports
8096 HTTP, 8920 HTTPS, 7359/UDP discovery
Port to forward
443 to your proxy
Settings page
Dashboard → Networking
Watch out for
Upload speed on FTTC lines

VPN or public address?

If only you and your household watch away from home, the simplest safe option is a VPN: WireGuard or Tailscale (Jellyfin’s documentation has a Tailscale page). The Jellyfin apps on phones and laptops work over a VPN without changes.

You need a public HTTPS address when someone else watches your library, or when a device can’t run a VPN – most smart TV, Roku and Fire TV sticks. That is what the rest of this guide sets up. It needs a public IP address; check you are not behind CGNAT first.

Jellyfin’s ports – and which to forward

PortUsed forForward it?
8096/TCPWeb interface and apps, plain HTTPNo – the proxy connects to it on your LAN
8920/TCPJellyfin’s own HTTPS, off by defaultNo
7359/UDPFinding servers on the local networkNever – it only works locally
443/TCPYour reverse proxyYes

Forwarding 8096 directly would send your login and everything else unencrypted, and on a .app name browsers won’t even try plain HTTP. Put a proxy in front.

1. Reverse proxy and Known proxies

Set up Caddy or Nginx Proxy Manager as in the HTTPS guide. With Caddy, the whole site block is:

Caddyfile
films.yourname.uk.app {
	reverse_proxy 192.168.1.30:8096
}

In Nginx Proxy Manager, create a proxy host for films.yourname.uk.app to http://192.168.1.30:8096 and tick Websockets Support – Jellyfin uses WebSockets for playback control and live updates.

Then tell Jellyfin about the proxy. Without this, Jellyfin sees every visitor as coming from the proxy’s LAN address, so it treats outside viewers as local and your remote‑access rules don’t apply.

  1. Open Dashboard → Networking.
  2. Under Firewall and Proxy Settings, set Known proxies to your proxy’s address, for example 192.168.1.40 (or 127.0.0.1 if the proxy runs on the same machine).
  3. Check LAN networks lists your home range, such as 192.168.1.0/24. Jellyfin uses it to decide who is “local”.
  4. Under Remote Access Settings, make sure Allow remote connections to this server is on.
  5. Save and restart Jellyfin.

Note

Jellyfin 12 prints a warning in its log if a subnet in the network or proxy settings is invalid. If remote viewers are treated as local after you save, check the log for that warning.

2. Decide who may connect from outside

Each user has their own switch under Dashboard → Users → (user) → Allow remote connections to this server. Turn it off for accounts that only ever watch at home, and consider a separate, non‑administrator account for yourself for everyday viewing away from home.

Jellyfin doesn’t have built‑in two‑factor sign‑in, so use long, unique passwords for every account that can connect remotely, and remove old accounts.

3. Match streaming to your upload speed

When you watch away from home, the video travels over your upload. Many UK part‑fibre (FTTC) lines upload at 10–20 Mbps, while full‑fibre lines often upload at 100 Mbps or more. A 4K remux can need far more than an FTTC line can send.

Set a ceiling under Dashboard → Playback → Streaming → Internet streaming bitrate limit (Mbps). About 70% of your measured upload speed, divided by the number of people who might watch at once, is a sensible starting point. Jellyfin will then transcode down instead of stuttering – which needs a reasonably capable CPU or hardware transcoding.

4. Forward 443 on your router

Forward TCP 443 (and 80, if your proxy uses HTTP‑01 certificates) to the proxy machine: BT, Virgin Media, Sky, TP‑Link, OpenWrt.

5. Keep the name pointing home

Jellyfin has no dynamic DNS feature of its own, so run the updater on whatever is always on: your router (OpenWrt), your NAS (Synology) or the Jellyfin machine itself. On a Linux host, the five‑minute cron job in the start guide updates home.yourname.uk.app using your uk.app DDNS token. Then add a CNAME record films → home.yourname.uk.app in the uk.app DNS settings.

6. Connect the apps

In each Jellyfin app, add a server with the address https://films.yourname.uk.app – no port number, because the proxy listens on the standard HTTPS port. At home, the apps usually find the server themselves on the LAN; away from home they use the name.

Tip

Some Chromecast and Google TV devices ignore your router’s DNS and use Google’s. That is fine for a public name like this one, but it is why local‑only names often fail on those devices.

7. Check it from outside

  1. Does the name point home? Look up films.yourname.uk.app with the DNS lookup and compare the A record with the address on ip.uk.app. After a change, the propagation checker shows which resolvers still have the old one.
  2. Is the port open from the internet? Run the open port checker against port 443. “Open” means your router forwards it and something answers. “Closed” or “timed out” means the forward, the device’s own firewall or CGNAT is in the way.
  3. Is the certificate right? The SSL checker shows whether the certificate covers the exact name, who issued it and when it expires.
  4. Is Jellyfin seeing real addresses? Play something over mobile data, then look at Dashboard → Activity. The session should show your phone’s public IP, not the proxy’s LAN address. If it shows the proxy, Known proxies isn’t set correctly.
  5. Test from outside for real. Turn Wi‑Fi off on your phone and open the address over mobile data. Testing from inside your own network can give misleading results.

If it doesn’t work

  • Apps connect, but playback never starts – usually WebSockets or a proxy timeout. Check the WebSockets option, and raise the proxy’s read timeout if you use plain Nginx.
  • Buffering on every film – your upload can’t keep up; lower the internet streaming bitrate limit.
  • Works in a browser but not in one TV app – make sure you entered the address with https://; some apps assume plain HTTP when no scheme is given.
  • Port closed – check double NAT and CGNAT.

A name for your next idea

Give your website, home server or next project a memorable address: yourname.uk.app. Choose your name and check availability before registering.

Find your name

Questions people ask

Can I use Jellyfin’s built‑in HTTPS instead of a proxy?

It is possible – enable HTTPS in Networking and supply a PKCS #12 certificate – but the Jellyfin documentation strongly recommends terminating HTTPS on a reverse proxy instead. Renewing certificates is also easier on the proxy.

Does Jellyfin need a subscription for remote streaming?

No. Jellyfin is free and open source, with no paid tiers and no relay service.

Should I set a Base URL?

Not if you use a separate name such as films.yourname.uk.app. A Base URL (serving Jellyfin under a path like /jellyfin) is known to break some clients and integrations.

How much upload speed do I need?

Roughly 4–8 Mbps for a good 1080p stream per viewer, and 20 Mbps or more for 4K. Transcoding can lower that at the cost of CPU.

Sources and further reading

We check each guide against the vendor’s own documentation and support forums. If something has changed on your firmware, tell us.

Partners