Remote access is one of Plex’s best features — and one of its most frustrating when it doesn’t work. You should be able to stream your library from anywhere, but instead you see “Not available outside your network” in Plex settings. Here’s how to fix it, no matter what’s causing the problem.
How Plex Remote Access Works
Your Plex server listens on port 32400 (TCP). For remote access to work, external connections from the internet need to reach that port on your server. This requires:
- Your router forwards port 32400 from its WAN (public) IP to your server’s LAN IP
- Your firewall allows incoming connections on port 32400
- Plex’s servers can verify the connection by reaching your public IP on that port
When any of these fail, Plex falls back to relay mode — which routes traffic through Plex’s servers at limited bandwidth (2 Mbps for free, 10 Mbps with Plex Pass). Relay mode is slow and unsuitable for 4K.
Step 1: Check Plex Settings
Go to Settings → Remote Access in your Plex server. You should see one of three statuses:
- Green checkmark “Fully accessible outside your network” — everything is working
- “Available outside your network (with limitations)” — relay mode, port forwarding not working
- “Not available outside your network” — nothing is working
If it shows “Retry” — click it. Sometimes the check just times out and a retry fixes it.
Step 2: Set Up Port Forwarding
Log into your router (usually at 192.168.1.1 or 192.168.0.1) and create a port forwarding rule:
- External port: 32400
- Internal port: 32400
- Protocol: TCP
- Internal IP: Your Plex server’s local IP address (e.g., 192.168.1.50)
Important: Give your Plex server a static IP (or a DHCP reservation) so the port forward doesn’t break when the server gets a new IP after a reboot.
Step 3: Check for Double NAT
Double NAT happens when you have two routers in series — common when your ISP provides a modem/router combo and you add your own router. Your port forward on Router #2 doesn’t help because Router #1 blocks the traffic before it reaches Router #2.
How to detect: Go to Plex Settings → Remote Access. If the “Public IP” shown doesn’t match what you see at whatismyip.com, or if your router’s WAN IP starts with 192.168.x.x or 10.x.x.x, you have double NAT.
Fixes:
- Put the ISP modem/router in bridge mode (disables its router function)
- Set up port forwarding on both routers
- Connect directly to the ISP modem and remove the second router
Step 4: Check for CGNAT
Carrier-Grade NAT (CGNAT) is when your ISP shares a single public IP among multiple customers. You don’t get your own public IP, so port forwarding is impossible.
How to detect: Log into your router and check the WAN IP. If it’s in the 100.64.x.x – 100.127.x.x range, you’re behind CGNAT.
Fixes:
- Call your ISP and request a public IP (some charge $5-10/month, some provide it free)
- Use a VPN with port forwarding (Mullvad, AirVPN)
- Set up a Cloudflare Tunnel or Tailscale to bypass NAT entirely
Step 5: Firewall Rules
Even with port forwarding, a firewall on the server itself can block connections:
- Windows: Windows Defender Firewall → Inbound Rules → ensure a rule allows TCP 32400. Plex usually creates this automatically during install
- Linux: Check
ufw statusoriptables -L. Add:sudo ufw allow 32400/tcp - Docker: If using host networking, the host firewall applies. If using bridge networking, Docker manages port mapping
VPN Conflicts
If your server runs a VPN client (for privacy), it may route Plex traffic through the VPN tunnel, breaking remote access. Fix by either:
- Adding a split tunnel exception for Plex (exclude port 32400 from the VPN)
- Running Plex in a separate Docker network that doesn’t use the VPN
- Binding Plex to your LAN interface instead of the VPN interface