Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Unable to forward Plex for direct connection

Hi everyone, 

I just upgraded my old sophos UTM, to the new XG firewall (SFOS 19).  Now I can't make my Plex server accessible from internet.  I try to use de DNAT server assistant, but it doesn't work.   Did someone manage to permit direct connexion for Plex media server ?

thank you very much 

Eric



This thread was automatically locked due to age.
Parents
  • Hello ,

    Thank you for reaching out to the community, could you please share the configuration of the DNAT which you created with the DNAT Server assistant. Also ensure the plex services is running on the internal server and is accessible locally. 

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Hi Vivek, 

    thank for the answer.  The configuration I created is pretty straight forward.  I specified the following ;

    -Internal Plex server at address 172.16.2.2,

    -The wan address : 137.175.20.20

    -the service used for the rules : TCP SOURCE : 55000 TCP DEST : 32400  UDP SOURCE : 55000  TCP DEST : 32400

    From there, the DNAT assistant created the firewall rule and the DNAT, REFLEXIVE NAT and LOOPBACK.

    Do I need to specify a service in the DNAT or I must put 'Any' ?

    I wonder if the service I created for Plex is correct.  I did choose port 55000 in TCP/UDP to port 32400.

  • Hey ,

    Do not put service as "ANY" it is not recommended, it will be open and vulnerable. Specify the services.

    Could you share a screen shot for the service object when you create one...  

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Stumbled upon this whle searching for something else but quick comment. I wanted to ask if you are confident that the source port is 55000? It's much more common to have the source port be 1-65535 and destination port be 32400 in your case.

  • Hi!

    Can you send a screenshot of the Service, NAT and Firewall Rules?
    On the Plex Service you created over the Firewall you need to leave the source port as 1:65535, or else the policy won't work since It's expecting the client to reach the Firewall while using the source port (itself) on 55000.

    Meanwhile the Destination port is 32400, which is the default for Plex (Plex uses only TCP/32400 for remote access.). It should look like this: 

    If you need assistance, I can send two example screenshots of a Firewall & NAT Policy which will work as expected with Plex.

    Thanks!


    If a post solves your question use the 'Verify Answer' button.

    XG 115w Rev.3 8GB RAM v19.5 MR1 @ Home.

  • Hi Vivek, i remove ''Any'' from the service and replace it by 1:65335 for the source port and 32400 for the destination.  Maybe it's I don't understand it well, but can you explain me the difference between the ''Any'' and 1:65535 ?  I mean, if I specify 1:65535, does the firewall will forward any source port to the 32400 ? 

Reply
  • Hi Vivek, i remove ''Any'' from the service and replace it by 1:65335 for the source port and 32400 for the destination.  Maybe it's I don't understand it well, but can you explain me the difference between the ''Any'' and 1:65535 ?  I mean, if I specify 1:65535, does the firewall will forward any source port to the 32400 ? 

Children
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?