- 1 dedicated IP address
- 10 devices
- 5 open ports
- 100 GBbandwidth
- 20 Mbpsspeed
Behind CGNAT, no router setting makes Jellyfin reachable from outside. GetAStatic gives the Jellyfin machine its own static IPv4 over WireGuard, from $2/mo. Open 443 to a reverse proxy such as Caddy, keep 8096 closed, and the apps connect by name.
Not affiliated with the Jellyfin project. Ports and settings as listed in Jellyfin's documentation, checked 2026-10-07.
Updated
| Web UI and apps (HTTP) | 8096 TCP, changeable in Dashboard → Networking |
|---|---|
| Built-in HTTPS | 8920 TCP, off by default. Jellyfin recommends HTTPS on a reverse proxy instead |
| Client discovery | 7359 UDP, local network only. Not for the internet |
| Remote access switch | Networking → Remote Access Settings, and per user: "Allow remote connections to this server" |
| Reverse proxy ports | 80 and 443 TCP (443 UDP too for HTTP/3) |
| Upload for remote viewers | At least 20 Mbps recommended |
Checked .
At home, the Jellyfin apps find your server by a broadcast on 7359 UDP, or you type an address such as http://192.168.1.20:8096. Neither one touches the internet. So a working app on the sofa tells you only that Jellyfin runs, not that anyone outside can reach it.
Jellyfin has no cloud account and no relay. A remote app must open a connection straight to your server, so something on the internet side has to accept it and pass it in. Normally that is a port forward on your router. Behind CGNAT, the router's WAN address is itself a shared ISP address, often in 100.64.0.0/10. The ISP's NAT drops the incoming connection before it ever reaches your router, and the forward rule never fires.
Even with a real public IP, Jellyfin's own documentation calls opening a port directly to the internet insecure and not recommended. Plain 8096 is HTTP: your password and every request cross the internet unencrypted. A good fix needs two parts: an address that reaches your home, and HTTPS answering on it.
Your own static IP over WireGuard. No VPS.
Dedicated IPv4 from $2/mo →Remote access on, but the server is behind CGNAT: your router cannot fix it. You need an address that arrives through a connection your side starts.
GetAStatic gives you a dedicated static IPv4 in Kansas City, Missouri or San Jose, California. WireGuard on the Jellyfin machine, or on your router, connects out to our node on UDP 1194 or 443, which CGNAT lets through. The path for a viewer is: Jellyfin app → your IP on 443 → our node → the WireGuard tunnel → Caddy on your server → Jellyfin on 127.0.0.1:8096.
Every port on the IP starts closed. You open 80 and 443 for the proxy in the dashboard, and nothing else. There is no UPnP and nothing opens itself, so Jellyfin's 8096 and 8920 cannot be reached from the internet even though the server is now public. Caddy fetches a free certificate on its own and serves Jellyfin over HTTPS, which is the setup Jellyfin's own reverse-proxy guide recommends.
A domain is not required to reach the IP, but Jellyfin's Caddy guide assumes one: an A record such as jellyfin.example.com pointing at your public IP. Because the IP is static, you create that record once and never need dynamic DNS. Viewers then type a name instead of an address and port.
This example runs the tunnel and Caddy on the Linux machine that runs Jellyfin. Docker works the same way if the tunnel and Caddy run on the host and the Jellyfin container publishes 8096 there.
| Port | Protocol | Used for |
|---|---|---|
| 443 | TCP | Caddy over HTTPS: the address the apps use. Open |
| 80 | TCP | Certificate checks and redirect to HTTPS. Open |
| 443 | UDP | HTTP/3 through Caddy. Optional |
| 8096 | TCP | Jellyfin HTTP. Keep closed: Caddy reaches it locally |
| 8920 | TCP | Jellyfin's own HTTPS. Keep closed and leave it off |
| 7359 | UDP | Local client discovery. Never open |
jellyfin.example.com {
reverse_proxy 127.0.0.1:8096
}These ports fit in Plus's 5 open ports. For speed, Jellyfin's hardware guide asks for at least 20 Mbps of upload for remote access, and below 100 Mbps suggests capping Jellyfin's internet streaming at about 70% of it. Use your plan's cap as that upload figure: 20 Mbps on Plus, 100 Mbps on Pro.
Plus for light use, Pro for most people, Ultra for full gigabit.
5× speed · 10× bandwidth · 2 IPs — only $2/mo more
With the Caddy setup above, https://jellyfin.example.com with no port, because Caddy answers on 443. Without a domain, http://YOUR-IP:8096 would connect if you opened 8096, but it sends your password unencrypted, which is what Jellyfin's documentation warns against.
Jellyfin sees the proxy's address, 127.0.0.1, instead of the viewer's. Until 127.0.0.1 is listed under Known Proxies, Jellyfin ignores the X-Forwarded-For header and cannot tell local from remote viewers, so its limits for external access stop working. Add it, and check that Local Networks lists only your LAN.
No. Discovery on 7359 UDP is a local broadcast and Jellyfin says not to expose it. Away from home, you add the server once by its address, and the app remembers it.
Yes. Set Base URL in Dashboard → Networking, restart Jellyfin, and match the path in Caddy. Some apps, such as the Android TV app, need the path in the server address. Jellyfin lists Base URL as breaking DLNA, HDHomeRun, Sonarr and Radarr, so a subdomain is simpler.
It depends on bitrate. Divide your plan's speed cap by each stream's bitrate, then keep some headroom. On Plus (20 Mbps) that is one or two transcoded streams; Pro (100 Mbps) fits several. Set an internet streaming limit in Jellyfin so remote viewers get a transcode instead of the full file.
Have more questions? See the full FAQ →