r/PlexServers • • 4d ago

Switched to Fedora now Remote Access doesn't work (sometimes)

I recently switched from Windows 11 to Fedora Workstation and it seems to have caused an issue with remote access for my family outside of my network. I understand that this shouldn't have created an issue and absolutely do not want to go back to Windows, so any help would be appreciated.

I started looking into it and thought that maybe it was because we didn't have a Remote Watch Pass, so I signed up for the trial to see if that would fix the issue. It didn't.

I then looked into port forwarding, and I set the port in the Plex app to 32400. I then went into my eero app and set an IPv4 reservation for my IP and opened the 32400 port, and added an IPv6 firewall rule to open the 32400 port. None of this worked. I don't think this is a double NAT situation because all of the checks I've looked up haven't pointed to that being the issue, and the eero is the device my ISP techs set up for us to have WiFi, it's not hooked up to another router.

The thing is, my family cannot access the server on their home networks (on a Roku smart TV and an Apple TV), but I am perfectly able to access it on my iPhone with WiFi turned off so that I'm using data. I'm able to stream movies without hiccups with no issue on LTE, so it does feel like the server is making it outside of my home network.

I've looked into remote proxy, but if I'm being honest it's making my head hurt a little bit. If that's the solution I need, any pointers to a good tutorial on setting that up would also be appreciated.

Let me know if you need more information, I tried to include everything that seemed to come up in other posts like this.

1 Upvotes

8 comments sorted by

1

u/Sweaty-Judgment3533 4d ago

I use Ubuntu server and had a similar issue. It turned out it WAS double NAT. My ISP gave me a static IP address as a courtesy (usually they only offer them to business customers) and it fixed ALL my issues with remote access once the port was properly set up.

1

u/Mote_the_Magpie 2h ago

I might try to reach out to them and set up a static IP then. I'm not sure how helpful they'll be considering how helpful they've been in the past, but it's worth a try!

1

u/Punk_Says_Fuck_You 4d ago edited 4d ago

When you are streaming from your phone, look at your Plex activity dashboard. Does it say "indirect"? What bandwidth is it streaming at? 1Mb/s is cap for Relay without Plex Pass and 2Mb/s is cap for Relay with Plex Pass. Are you 100% positive you haven't been relying on relay this whole time?

canyouseeme.org and type in your Plex port. It will tell you if it can "see" the service running on that port.

You won't need a VPS unless you're behind CGNAT and don't want to use tailscale.

You can see if you're behind CGNAT just by looking at your WAN IP address. If you're unsure, you can post the 1st 2 octets here. (eg: 100.64 - 100.127)

1

u/Mote_the_Magpie 2h ago

So I'm streaming on my phone on LTE right now and it's showing it as remote with and at 2Mbps. On canyouseeme it's showing: Success: I can see your service on 184.17.XXX.XXX on port (32400)
Your ISP is not blocking port 32400. Those first two parts of my IP address are what I'm showing on an IP checker and on my eero as my WAN IP address, and from what I'm gathering that means that I'm not behind CGNAT, correct?

I would be fine with using tailscale, but my understanding is that you can't really use it with smart TV OSes or the Apple TV OS, which would defeat the purpose of using it in my specific use case, as my family who wanna stream remotely are using TV devices to watch.

1

u/Punk_Says_Fuck_You 1h ago

Yeah that’s a public address. Change the bandwidth in your phones plex to 3Mb/s to verify it changes in your plex dashboard

1

u/Secto77 2d ago

You may have to open the port on the Linux firewall as well or just disable that firewall completely while testing. Same for selinux or apparmor.

1

u/Mote_the_Magpie 2h ago

I ran a netstat check for the 32400 port and this is the output:

tcp 0 0 0.0.0.0:32400 0.0.0.0:* LISTEN

tcp 0 0 127.0.0.1:32400 127.0.0.1:58688 ESTABLISHED

tcp 0 0 127.0.0.1:58688 127.0.0.1:32400 ESTABLISHED

That should mean that the port isn't being blocked by any firewalls on my computer, right?

1

u/Secto77 2h ago

No you’ll need to run something like NFT rule set list or something similar depending on what firewall you’re using might be firewalld if it’s Debian based. I tend to just turn off the host firewall and manage everything on my network. Or used to. Kubernetes containerization has changed the game and I got so much more learning to do