Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Unable to forward Plex for direct connection

Hi everyone, 

I just upgraded my old sophos UTM, to the new XG firewall (SFOS 19).  Now I can't make my Plex server accessible from internet.  I try to use de DNAT server assistant, but it doesn't work.   Did someone manage to permit direct connexion for Plex media server ?

thank you very much 

Eric



This thread was automatically locked due to age.
Parents Reply Children
  • Hi Vivek, 

    thank for the answer.  The configuration I created is pretty straight forward.  I specified the following ;

    -Internal Plex server at address 172.16.2.2,

    -The wan address : 137.175.20.20

    -the service used for the rules : TCP SOURCE : 55000 TCP DEST : 32400  UDP SOURCE : 55000  TCP DEST : 32400

    From there, the DNAT assistant created the firewall rule and the DNAT, REFLEXIVE NAT and LOOPBACK.

    Do I need to specify a service in the DNAT or I must put 'Any' ?

    I wonder if the service I created for Plex is correct.  I did choose port 55000 in TCP/UDP to port 32400.

  • Hey ,

    Do not put service as "ANY" it is not recommended, it will be open and vulnerable. Specify the services.

    Could you share a screen shot for the service object when you create one...  

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Stumbled upon this whle searching for something else but quick comment. I wanted to ask if you are confident that the source port is 55000? It's much more common to have the source port be 1-65535 and destination port be 32400 in your case.

  • Hi!

    Can you send a screenshot of the Service, NAT and Firewall Rules?
    On the Plex Service you created over the Firewall you need to leave the source port as 1:65535, or else the policy won't work since It's expecting the client to reach the Firewall while using the source port (itself) on 55000.

    Meanwhile the Destination port is 32400, which is the default for Plex (Plex uses only TCP/32400 for remote access.). It should look like this: 

    If you need assistance, I can send two example screenshots of a Firewall & NAT Policy which will work as expected with Plex.

    Thanks!


    If a post solves your question use the 'Verify Answer' button.

    XG 115w Rev.3 8GB RAM v19.5 MR1 @ Home.

  • Hi Vivek, i remove ''Any'' from the service and replace it by 1:65335 for the source port and 32400 for the destination.  Maybe it's I don't understand it well, but can you explain me the difference between the ''Any'' and 1:65535 ?  I mean, if I specify 1:65535, does the firewall will forward any source port to the 32400 ? 

  • Hi Christian, I tried to put the port range 1:65535 in the source of the service.  The destination is set to 32400, which is the port in use on the internal media agent.  Now it seem to work, but I wonder if its secure, since the source port are 1:65335.

  • Hey

    ANY = 1:65535 

    As in the world there are only 65,535 ports available. So by ANY it means any port falling in the range of 1:65535. 

    So For example if you are browsing to google.com, then you know that the google.com uses https Port i.e. 443. 

    So, the service object for 443 i.e. HTTPS traffic would be as follows: 

    Source range of Ports will be 1:65535. and destination Port will be just 443. 

    In your case it is plex so source range of ports will be 1:65535 and destination will be 32400. 

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Hi Prism, thank for answer.  After reading on Plex documentation, it seem they recommend another port for the external port since 32400 is a well know port.  It is possible to listen on another port on the wan interface and redirect it to the port 32400 for the internal server ?

  • Thank, so it's not a security issue to put 1:65535 on the source port and put 32400 for the destination ?  Sorry, I relatively newbie to the rules in Sophos :) 

  • Nope source could be any, as for any machine originating the traffic would pick up a random port, so yes you are safe and it is not a security issue...

    But when it comes to a destination port, "ANY" is not recommended. Better mention an explicit service only or it could be a range of ports depending upon the destination server's requirement. 

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?