Jellyfin remote access behind CGNAT

Behind CGNAT, no router setting makes Jellyfin reachable from outside. GetAStatic gives the Jellyfin machine its own static IPv4 over WireGuard, from $2/mo. Open 443 to a reverse proxy such as Caddy, keep 8096 closed, and the apps connect by name.

Not affiliated with the Jellyfin project. Ports and settings as listed in Jellyfin's documentation, checked 2026-10-07.

Instant setup US-based IP

Updated

Facts

Jellyfin networking: the facts

Web UI and apps (HTTP)8096 TCP, changeable in Dashboard → Networking
Built-in HTTPS8920 TCP, off by default. Jellyfin recommends HTTPS on a reverse proxy instead
Client discovery7359 UDP, local network only. Not for the internet
Remote access switchNetworking → Remote Access Settings, and per user: "Allow remote connections to this server"
Reverse proxy ports80 and 443 TCP (443 UDP too for HTTP/3)
Upload for remote viewersAt least 20 Mbps recommended

Checked .

The problem

Why Jellyfin works at home and not outside

At home, the Jellyfin apps find your server by a broadcast on 7359 UDP, or you type an address such as http://192.168.1.20:8096. Neither one touches the internet. So a working app on the sofa tells you only that Jellyfin runs, not that anyone outside can reach it.

Jellyfin has no cloud account and no relay. A remote app must open a connection straight to your server, so something on the internet side has to accept it and pass it in. Normally that is a port forward on your router. Behind CGNAT, the router's WAN address is itself a shared ISP address, often in 100.64.0.0/10. The ISP's NAT drops the incoming connection before it ever reaches your router, and the forward rule never fires.

Even with a real public IP, Jellyfin's own documentation calls opening a port directly to the internet insecure and not recommended. Plain 8096 is HTTP: your password and every request cross the internet unencrypted. A good fix needs two parts: an address that reaches your home, and HTTPS answering on it.

Your own static IP over WireGuard. No VPS.

Dedicated IPv4 from $2/mo →
Check

Find out which part is failing

  1. On your home Wi-Fi, open http://SERVER-LAN-IP:8096 in a browser. If it loads, Jellyfin itself is fine.
  2. In Jellyfin, check Dashboard → Networking → Remote Access Settings, and the user's "Allow remote connections to this server" box. With either one off, remote sign-ins fail even when the network is fine.
  3. Compare your router's WAN address with the address a "what is my IP" search shows. If they differ, something in front of your router does NAT. A WAN address between 100.64.0.0 and 100.127.255.255 means CGNAT. The CGNAT check does this for you.
  4. If you already forward a port on the router, try that port at the "what is my IP" address from a phone on mobile data. If it times out while the LAN address works, the connection is dropped before it reaches you.

Remote access on, but the server is behind CGNAT: your router cannot fix it. You need an address that arrives through a connection your side starts.

Why use GetAStatic?

Why Jellyfin owners use GetAStatic

  • The Jellyfin apps on TVs, phones and browsers connect to your own address, with nothing for viewers to install
  • Only the proxy's 80 and 443 face the internet; 8096 stays private
  • It works behind CGNAT because the tunnel connects out from your side
  • A fixed IP: one DNS record and one certificate name that never change
How it works

A static IP in front of a reverse proxy

GetAStatic gives you a dedicated static IPv4 in Kansas City, Missouri or San Jose, California. WireGuard on the Jellyfin machine, or on your router, connects out to our node on UDP 1194 or 443, which CGNAT lets through. The path for a viewer is: Jellyfin app → your IP on 443 → our node → the WireGuard tunnel → Caddy on your server → Jellyfin on 127.0.0.1:8096.

Every port on the IP starts closed. You open 80 and 443 for the proxy in the dashboard, and nothing else. There is no UPnP and nothing opens itself, so Jellyfin's 8096 and 8920 cannot be reached from the internet even though the server is now public. Caddy fetches a free certificate on its own and serves Jellyfin over HTTPS, which is the setup Jellyfin's own reverse-proxy guide recommends.

A domain is not required to reach the IP, but Jellyfin's Caddy guide assumes one: an A record such as jellyfin.example.com pointing at your public IP. Because the IP is static, you create that record once and never need dynamic DNS. Viewers then type a name instead of an address and port.

Setup

Set up Jellyfin with Caddy and a static IP

This example runs the tunnel and Caddy on the Linux machine that runs Jellyfin. Docker works the same way if the tunnel and Caddy run on the host and the Jellyfin container publishes 8096 there.

  1. Finish Jellyfin's setup on your LAN and confirm http://SERVER-LAN-IP:8096 works.
  2. Sign up for GetAStatic and note your static IP. In the dashboard, open 80 TCP and 443 TCP on it. Leave 8096, 8920 and 7359 closed.
  3. Import the WireGuard config on the Jellyfin machine and turn the tunnel on. If you run the tunnel on your router instead, forward 80 and 443 from the router to the Jellyfin machine.
  4. At your DNS provider, create an A record (for example jellyfin.example.com) pointing at the static IP.
  5. Install Caddy and use the Caddyfile below. On start, Caddy requests a certificate for the name and serves Jellyfin over HTTPS.
  6. In Jellyfin, open Dashboard → Networking. Add 127.0.0.1 under Known Proxies, set Local Networks to your LAN (for example 192.168.1.0/24), allow remote connections, save and restart Jellyfin.
  7. Under Users → Edit User, tick "Allow remote connections to this server" only for people who watch from outside.
  8. On a phone on mobile data, add the server https://jellyfin.example.com in the Jellyfin app and sign in. Then run the port check on 8096: it should show closed.
PortProtocolUsed for
443TCPCaddy over HTTPS: the address the apps use. Open
80TCPCertificate checks and redirect to HTTPS. Open
443UDPHTTP/3 through Caddy. Optional
8096TCPJellyfin HTTP. Keep closed: Caddy reaches it locally
8920TCPJellyfin's own HTTPS. Keep closed and leave it off
7359UDPLocal client discovery. Never open
jellyfin.example.com {
    reverse_proxy 127.0.0.1:8096
}

These ports fit in Plus's 5 open ports. For speed, Jellyfin's hardware guide asks for at least 20 Mbps of upload for remote access, and below 100 Mbps suggests capping Jellyfin's internet streaming at about 70% of it. Use your plan's cap as that upload figure: 20 Mbps on Plus, 100 Mbps on Pro.

Good to know

Good to know

  • Each IP is one WireGuard config, active on one device at a time. Run it on a router and every device behind it shares the IP; the plan card's device figure is a guide, not a cap.
  • The machine running the tunnel sends all its traffic through the IP, including Jellyfin's metadata downloads and system updates. Remote streams count against your monthly data (100 GB on Plus, 1 TB on Pro), and the speed cap applies in both directions.
  • At home, keep using the LAN address or a local DNS name. If home devices use the public name, each stream leaves through your ISP, goes to Kansas City, Missouri or San Jose, California and comes back, and counts against your data.
  • It is a datacenter IP in Kansas City, Missouri or San Jose, California. Viewers far from the IP's city see more delay, and playback can take a moment longer to start.
  • Jellyfin sometimes puts an api_key in request URLs. Do not keep full request URLs in your proxy's access logs, or protect those logs.
  • If your ISP already gives you a public, unshared IP, you may not need us: forward 80 and 443 on your router to the proxy instead.
Pricing

Choose your plan

Plus for light use, Pro for most people, Ultra for full gigabit.

Plus
$2/mo

 

  • 1 dedicated IP address
  • 10 devices
  • 5 open ports
  • 100 GBbandwidth
  • 20 Mbpsspeed
Ultra
$10/mo

 

  • 2 dedicated IP addresses
  • Unlimited devices
  • Unlimited open ports
  • 5 TBbandwidth
  • 1 Gbpsspeed
  • Inbound + outbound access
  • Instant activation
  • 7-day money-back guarantee
  • Cancel anytime
Add-ons, per IP addressCustom hostname $5·Addtl. IP $2/mo (Ultra $7/mo)·Gigabit Speed (Plus & Pro) $5/mo·SMTP $25
FAQ

Questions, answered.

01What server address do I enter in the Jellyfin app?

With the Caddy setup above, https://jellyfin.example.com with no port, because Caddy answers on 443. Without a domain, http://YOUR-IP:8096 would connect if you opened 8096, but it sends your password unencrypted, which is what Jellyfin's documentation warns against.

02Why do remote viewers count as local after I added Caddy?

Jellyfin sees the proxy's address, 127.0.0.1, instead of the viewer's. Until 127.0.0.1 is listed under Known Proxies, Jellyfin ignores the X-Forwarded-For header and cannot tell local from remote viewers, so its limits for external access stop working. Add it, and check that Local Networks lists only your LAN.

03Will the apps find my server automatically when I am away?

No. Discovery on 7359 UDP is a local broadcast and Jellyfin says not to expose it. Away from home, you add the server once by its address, and the app remembers it.

04Can I serve Jellyfin under a path such as /jellyfin?

Yes. Set Base URL in Dashboard → Networking, restart Jellyfin, and match the path in Caddy. Some apps, such as the Android TV app, need the path in the server address. Jellyfin lists Base URL as breaking DLNA, HDHomeRun, Sonarr and Radarr, so a subdomain is simpler.

05How many people can stream at once?

It depends on bitrate. Divide your plan's speed cap by each stream's bitrate, then keep some headroom. On Plus (20 Mbps) that is one or two transcoded streams; Pro (100 Mbps) fits several. Set an internet streaming limit in Jellyfin so remote viewers get a transcode instead of the full file.

Have more questions? See the full FAQ →