Fix Plex Remote Access behind CGNAT

Give your Plex server its own public IPv4. GetAStatic is a WireGuard VPN that tunnels a static IP to the Plex machine, from $2/mo. Open port 32400 and Plex shows "Fully accessible outside your network". The same fix works for Jellyfin.

Instant setup US-based IP

Updated

Facts

Plex and Jellyfin remote access: the facts

Plex Relay speedAbout 2 Mbps per stream (lower without Plex Pass)
Plex remote streamingNeeds Plex Pass or a Remote Watch Pass (since 29 Apr 2025)
Plex port32400 TCP
Jellyfin relayNone: it needs an inbound connection
Jellyfin ports8096 TCP (HTTP), 8920 TCP (HTTPS), or 443 through a reverse proxy

Checked .

The problem

Why Plex Remote Access fails

You turn on Remote Access in Plex and it stays red: "Not available outside your network". You forward port 32400 on your router and nothing changes.

The cause is usually CGNAT. Your ISP shares one public IP among many homes, so your router never gets a public address of its own. A port forward on your router cannot work, because the ISP's equipment in front of it drops the incoming connection. Starlink, T-Mobile and Verizon 5G Home Internet, and many cable and fiber ISPs work this way. How to escape CGNAT explains the options.

Plex then falls back to Plex Relay. Relay works, but Plex limits relayed video to about 2 Mbps, so remote viewers get a blurry, low-resolution stream.

Pricing

Choose your plan

Plus for light use, Pro for most people, Ultra for full gigabit.

Plus
$2/mo

 

  • 1 dedicated IP address
  • 10 devices
  • 5 open ports
  • 100 GBbandwidth
  • 20 Mbpsspeed
Ultra
$10/mo

 

  • 2 dedicated IP addresses
  • Unlimited devices
  • Unlimited open ports
  • 5 TBbandwidth
  • 1 Gbpsspeed
  • Inbound + outbound access
  • Instant activation
  • 7-day money-back guarantee
  • Cancel anytime
Add-ons, per IP addressCustom hostname $5·Addtl. IP $2/mo (Ultra $7/mo)·Gigabit Speed (Plus & Pro) $5/mo·SMTP $25
Why use GetAStatic?

Why Plex users pick GetAStatic

  • Direct connections at full quality, not the slow Plex Relay
  • Works on Starlink, T-Mobile and Verizon 5G Home, and other CGNAT ISPs
  • Any Plex or Jellyfin app can connect: no extra software for the people who watch
  • No router changes and no business internet plan
How it works

Give Plex its own public IP

GetAStatic gives you a dedicated static IPv4 address. The Plex machine connects out to our node in Kansas City, Missouri or San Jose, California over WireGuard, so CGNAT does not block it. Connections to your IP on the ports you open come down the tunnel to Plex.

The whole machine uses the IP, so Plex sees it as your public address. Remote viewers connect to it directly, and Relay is no longer needed.

Jellyfin is harder behind CGNAT, because it has no relay at all. Remote apps must reach the server directly, on 8096 (HTTP), 8920 (HTTPS), or 443 through a reverse proxy. With a static IP you open that port, point a DNS name at the IP, and every Jellyfin app can connect.

Setup

Set up Plex with a static IP

Run WireGuard on the computer or NAS that runs Plex Media Server, or on your router.

  1. Sign up for GetAStatic and note your static IP.
  2. In the dashboard, open port 32400 TCP on that IP.
  3. Download the WireGuard config and import it into the WireGuard app on the Plex machine. Turn the tunnel on.
  4. In Plex, go to Settings → Remote Access. Tick "Manually specify public port" and enter 32400.
  5. Click Apply or Retry. The status should turn green: "Fully accessible outside your network".
  6. For Jellyfin, open 8096 TCP instead, or 443 TCP if you put a reverse proxy such as Caddy in front of it for HTTPS.
PortProtocolUsed for
32400TCPPlex Media Server
8096TCPJellyfin (HTTP)
443TCPJellyfin through your own reverse proxy (HTTPS)

Plan for bandwidth. A remote 1080p stream is roughly 4–10 Mbps; 4K needs much more. The speed cap is per IP and the same in both directions, so Plus (20 Mbps) fits one modest stream and Pro (100 Mbps) fits several. Every GB you stream counts against your monthly allowance: 100 GB on Plus, 1 TB on Pro.

Good to know

Limits to know

  • Your plan's speed cap and monthly bandwidth apply to everything you stream. Set a remote quality limit in Plex or Jellyfin if you share with many people.
  • All traffic passes through Kansas City, Missouri or San Jose, California. Viewers far from the IP's city will see more delay, and the stream can take a little longer to start.
  • A Plex account and any Plex subscription are separate. We do not sell or include them.
  • Every open port is reachable by anyone. Keep Plex and Jellyfin updated and use strong passwords.
  • The IP is a datacenter IP, not a home IP. That is fine for Plex and Jellyfin.
FAQ

Questions, answered.

01Do I still need Plex Pass?

Plex's own rules do not change. Since April 2025, remote video streaming needs a Plex Pass on the server owner's account or a Remote Watch Pass on the viewer's account. GetAStatic only fixes the connection.

02Does this work for Jellyfin?

Yes. Jellyfin has no relay, so behind CGNAT it needs an inbound port. Open 8096 TCP on your static IP, or 443 TCP if you run a reverse proxy for HTTPS. Cloudflare Tunnel is a poor fit: Cloudflare's free-plan terms do not allow serving video through its network.

03Why not a free VPS and Tailscale?

A free cloud VPS (such as Oracle's free tier) plus Tailscale can forward ports to your home, and it costs nothing. But you set up and maintain the VPS, the forwarding rules and its firewall yourself, the provider can reclaim idle free instances, and every stream takes two hops. GetAStatic is one WireGuard config with the IP already routed, from $2/mo.

04Do I need to change my router?

No. The tunnel starts from the Plex machine and goes out through your normal internet. You do not need a port forward or a new modem.

05Can I run Plex in Docker or on a NAS?

Yes, if WireGuard runs on the same host as Plex (with Plex on the host network) or on your router.

06Why not use Tailscale alone?

With Tailscale alone, every viewer must install Tailscale and join your network. A public IP works with any Plex app on any TV, phone or browser, with nothing extra to install.

Have more questions? See the full FAQ →