- 1 dedicated IP address
- 10 devices
- 5 open ports
- 100 GBbandwidth
- 20 Mbpsspeed
Give your Plex server its own public IPv4. GetAStatic is a WireGuard VPN that tunnels a static IP to the Plex machine, from $2/mo. Open port 32400 and Plex shows "Fully accessible outside your network". The same fix works for Jellyfin.
Updated
| Plex Relay speed | About 2 Mbps per stream (lower without Plex Pass) |
|---|---|
| Plex remote streaming | Needs Plex Pass or a Remote Watch Pass (since 29 Apr 2025) |
| Plex port | 32400 TCP |
| Jellyfin relay | None: it needs an inbound connection |
| Jellyfin ports | 8096 TCP (HTTP), 8920 TCP (HTTPS), or 443 through a reverse proxy |
Checked .
You turn on Remote Access in Plex and it stays red: "Not available outside your network". You forward port 32400 on your router and nothing changes.
The cause is usually CGNAT. Your ISP shares one public IP among many homes, so your router never gets a public address of its own. A port forward on your router cannot work, because the ISP's equipment in front of it drops the incoming connection. Starlink, T-Mobile and Verizon 5G Home Internet, and many cable and fiber ISPs work this way. How to escape CGNAT explains the options.
Plex then falls back to Plex Relay. Relay works, but Plex limits relayed video to about 2 Mbps, so remote viewers get a blurry, low-resolution stream.
Plus for light use, Pro for most people, Ultra for full gigabit.
5× speed · 10× bandwidth · 2 IPs — only $2/mo more
GetAStatic gives you a dedicated static IPv4 address. The Plex machine connects out to our node in Kansas City, Missouri or San Jose, California over WireGuard, so CGNAT does not block it. Connections to your IP on the ports you open come down the tunnel to Plex.
The whole machine uses the IP, so Plex sees it as your public address. Remote viewers connect to it directly, and Relay is no longer needed.
Jellyfin is harder behind CGNAT, because it has no relay at all. Remote apps must reach the server directly, on 8096 (HTTP), 8920 (HTTPS), or 443 through a reverse proxy. With a static IP you open that port, point a DNS name at the IP, and every Jellyfin app can connect.
Run WireGuard on the computer or NAS that runs Plex Media Server, or on your router.
| Port | Protocol | Used for |
|---|---|---|
| 32400 | TCP | Plex Media Server |
| 8096 | TCP | Jellyfin (HTTP) |
| 443 | TCP | Jellyfin through your own reverse proxy (HTTPS) |
Plan for bandwidth. A remote 1080p stream is roughly 4–10 Mbps; 4K needs much more. The speed cap is per IP and the same in both directions, so Plus (20 Mbps) fits one modest stream and Pro (100 Mbps) fits several. Every GB you stream counts against your monthly allowance: 100 GB on Plus, 1 TB on Pro.
Plex's own rules do not change. Since April 2025, remote video streaming needs a Plex Pass on the server owner's account or a Remote Watch Pass on the viewer's account. GetAStatic only fixes the connection.
Yes. Jellyfin has no relay, so behind CGNAT it needs an inbound port. Open 8096 TCP on your static IP, or 443 TCP if you run a reverse proxy for HTTPS. Cloudflare Tunnel is a poor fit: Cloudflare's free-plan terms do not allow serving video through its network.
A free cloud VPS (such as Oracle's free tier) plus Tailscale can forward ports to your home, and it costs nothing. But you set up and maintain the VPS, the forwarding rules and its firewall yourself, the provider can reclaim idle free instances, and every stream takes two hops. GetAStatic is one WireGuard config with the IP already routed, from $2/mo.
No. The tunnel starts from the Plex machine and goes out through your normal internet. You do not need a port forward or a new modem.
Yes, if WireGuard runs on the same host as Plex (with Plex on the host network) or on your router.
With Tailscale alone, every viewer must install Tailscale and join your network. A public IP works with any Plex app on any TV, phone or browser, with nothing extra to install.
Have more questions? See the full FAQ →