First: the 2025 remote playback rules
Since 29 April 2025, streaming personal video from a Plex Media Server to a device outside your home network needs one of these:
- the server owner’s account has an active Plex Pass (which covers everyone streaming from that server), or
- the viewer’s own account has a Plex Pass or a Remote Watch Pass.
Music to Plexamp and photos are not affected. Plex has been rolling the rule out app by app; mobile, web, desktop, Roku, smart TVs, PlayStation and Xbox are covered. So if remote access shows as working but a family member is told to buy a pass, nothing is wrong with your network.
Being counted as remote when you are at home
Plex decides “remote” by whether the app can reach the server directly on the same local network. VPNs, containers without host networking, separate subnets and routers that block DNS rebinding can all make a device at home look remote. See DNS rebinding below.
1. Turn on remote access with a fixed port
- Open Plex Web, sign in as the server owner, and go to Settings → Server → Remote Access. Click Show Advanced.
- Tick Manually specify public port and enter
32400. (You can use any port from 20000 to 50000 on the outside if you prefer; the inside is always 32400.) - On your router, forward TCP
32400to the Plex server’s LAN address, port32400. Give the server a fixed address with a DHCP reservation first. - Back in Plex, click Retry or Apply. After a few seconds it should say Fully accessible outside your network.
Router steps: BT, Virgin Media, Sky, TP‑Link, OpenWrt. If you run two Plex servers, give each a different external port (32401, 32402…) that forwards to 32400 on each machine.
Tip
Plex can also open the port by itself with UPnP or NAT‑PMP if your router allows it. A manual forward is more predictable and survives router restarts, so we recommend it – and turn UPnP off afterwards if nothing else needs it.
2. Still red? Work through the usual causes
Double NAT
Compare the WAN IPv4 address on your router’s status page with the address on ip.uk.app. If your router shows 192.168.x.x or 10.x.x.x, it sits behind another router – usually the ISP hub behind a mesh system. Fix it with modem mode, access‑point mode, or a forward on both boxes: see double NAT.
CGNAT
If the router’s WAN address is in 100.64.0.0–100.127.255.255, your provider shares one public address between customers and no port forward can work over IPv4. Plex will fall back to its Relay, which works but is bandwidth‑limited, so you will see low quality. The CGNAT guide lists the ways out, starting with asking for a public IP.
A firewall on the server
Windows Defender Firewall, ufw on Linux, or a NAS firewall can block incoming connections even when the router forwards them. Allow TCP 32400 on the server itself. (A BT Community thread where exactly this was the cause is in the sources.)
Docker
Plex in Docker should use host networking (network_mode: host) or publish 32400 and set Custom server access URLs. Bridge networking without that makes Plex announce an address nobody can reach.
Once the port is open, the open port checker should show 32400 as open on your public IP.
3. DNS rebinding: why the app at home says “remote”
Plex gives each server a secure address under plex.direct that resolves to your server’s LAN address. Some routers, Pi‑hole set‑ups and DNS filters block public names that answer with private addresses (“rebind protection”). The app then can’t connect locally and goes out through the internet or the relay instead.
Allow plex.direct as an exception to rebind protection in your router or DNS filter. On OpenWrt the setting lives under Network → DHCP and DNS; on other routers look for “DNS rebind protection” in the DNS or security settings. Plex’s Treat WAN IP As LAN Bandwidth setting (on by default) stops such connections being throttled as remote.
4. Optional: your own name with a trusted certificate
You don’t need your own name for Plex apps – they find the server through plex.tv. It is useful if you want a memorable address for the web app, or if you sometimes connect through a VPN or other set‑up where the plex.direct address doesn’t work. Plex supports a custom certificate on its own port, so no reverse proxy is needed.
- Keep a name pointed at home with dynamic DNS:
home.yourname.uk.appfrom your router, NAS or the cron job in the start guide, plus a CNAME recordplex→home.yourname.uk.appin the uk.app DNS settings. - Get a certificate for
plex.yourname.uk.app(or a wildcard) with DNS‑01 – no ports needed. The HTTPS guide has the acme.sh commands for uk.app. - Convert it into the PKCS #12 file Plex expects, protected by a passphrase:
openssl pkcs12 -export -out /var/lib/plexmediaserver/plex.p12 \
-inkey key.pem -in fullchain.pem \
-certpbe AES-256-CBC -keypbe AES-256-CBC -macalg SHA256 \
-passout pass:choose-a-passphrase
chown plex:plex /var/lib/plexmediaserver/plex.p12
chmod 600 /var/lib/plexmediaserver/plex.p12- In Settings → Server → Network (Show Advanced), fill in Custom certificate location (the
.p12path), Custom certificate encryption key (the passphrase) and Custom certificate domain (plex.yourname.uk.app). - Restart Plex Media Server. Plex publishes
https://plex.yourname.uk.app:32400to plex.tv using the port from the Remote Access page.
Run the conversion again after every renewal – acme.sh’s --reloadcmd can do it and restart Plex for you.
Using a reverse proxy instead
Prefer port 443? Put Plex behind your reverse proxy instead, and add https://plex.yourname.uk.app:443 to Custom server access URLs in the Network settings so plex.tv tells apps about it. Leave Secure connections on its default, Preferred.
5. Check it from outside
- Does the name point home? Look up
plex.yourname.uk.appwith the DNS lookup and compare the A record with the address on ip.uk.app. After a change, the propagation checker shows which resolvers still have the old one. - Is the port open from the internet? Run the open port checker against port 32400. “Open” means your router forwards it and something answers. “Closed” or “timed out” means the forward, the device’s own firewall or CGNAT is in the way.
- Is the certificate right? The SSL checker shows whether the certificate covers the exact name, who issued it and when it expires.
- Is Plex happy? The Remote Access page should show green and the public port. If it flips between green and red, something – often UPnP or a second router – keeps changing the mapping.
- Test from outside for real. Turn Wi‑Fi off on your phone and open the address over mobile data. Testing from inside your own network can give misleading results.