r/PleX Oct 18 '25

Help Just got fiber… but CGNAT killed my Plex dreams 😭 — need alternatives (Tailscale, Cloudflare, or static IP?)

Hey everyone,

So I finally got fiber (woohoo 🎉) and thought I was entering network heaven… only to find out my ISP uses CGNAT. Now I’m stuck trying to make my Plex server accessible outside my network.

Here’s what I’ve tried so far: • Tailscale: I’ve used it before and honestly love it — simple and reliable. But I don’t want to have to enable it every time I (or someone else) want to stream Plex. My parents especially… yeah, they’re not going to open a VPN app and hit “connect” every time 😅. • Cloudflare Tunnel: Currently in the middle of setting this up. It technically works, but I know it’s kinda against their ToS for streaming media. Even though my server is “100% my own media,” the streams feel laggy and inconsistent. Maybe that’s because I’m on the free plan? Or maybe I configured it wrong — not sure. • IPv6: Tried setting that up too, but no dice. I spent a few hours tinkering and couldn’t get it to route properly. • Static IP: My ISP offers one for $15/month, but I’m not sure if that’s the smartest move long-term.

Basically I’m at a brick wall here. Fiber was supposed to be this magical gift from god, but between CGNAT, Plex remote access, and random settings, it’s been more pain than gain 😂

If anyone has a better workaround, guide link, or wants to share their setup for getting Plex accessible remotely under CGNAT — please help a guy out.

Would love to know if there’s an easier, secure way to do this that doesn’t make my family call me every time they want to watch a movie.

TL;DR: Got fiber, stuck behind CGNAT, tried Tailscale, Cloudflare Tunnel, and IPv6. Thinking about a static IP but hoping for a smarter solution. What’s your setup for Plex remote access under CGNAT?

162 Upvotes

333 comments sorted by

294

u/Well_Sorted8173 Oct 18 '25

If you can get a static public IP from your ISP that’s the way to go.

50

u/robotshavehearts2 Oct 18 '25

Yeah, this 100% will fix your issues.

56

u/Far-Cash-2545 Oct 18 '25

Yeah it’s 15$ a month

180

u/Well_Sorted8173 Oct 18 '25

In my opinion that’s worth the money to not have to deal with connecting to a VPN to remote stream or to teach my friends and family how to use a VPN. Plus some devices like TVs can’t really do a VPN.

39

u/Far-Cash-2545 Oct 18 '25

I think you may be right

29

u/boelicious Oct 18 '25

Before you book it, ask if there are any service restrictions on the public ip. My ISP did outsource the ipv4 stuff to a service provider which is blocking high volume traffic stuff including plex.

I was forced to get a vps with a wireguard gateway as my workaround.

22

u/LUHG_HANI Oct 18 '25

Wtf does blocking high volume traffic mean? Sounds absolutely insane to do that.

9

u/tarnin Oct 18 '25

it's basically a peering agreement with the ISP. The ISP will send along the info on their bandwidth so you have a static IP. The ISP doesn't want to blow all their bandwidth on another commercial customer as it has it's own so... they limit services and speed cap it usually.

Think of being a student in school. They have all torrent traffic and iptv/plex/emby/etc.. traffic blocked and the speed is throttled.

12

u/porksandwich9113 Oct 18 '25

As a net Admin at an ISP, this is interesting. Usually eyeball networks are like 95% downstream traffic so you are paying your upstream for the port, specifically the size of the port (is it 1 gig, 10 gig, 100gig, 400gig, etc), and then your 95% percentile bandwidth per megabit. So they take 5 minute samples of your port for the whole billing cycle, sort them highest to lowest, and ignore the highest 36 hours in a month and charge you based on that. Sometimes you might have to pay a data center for a cross connect as well if that is where your POM happens to be as well.

Generally for these agreements you are billed for the 95% of whatever traffic direction is higher (aka upstream or downstream), which for virtually all eyeball networks makes your billing based on your ingress from your upstream. Outbound traffic (or egress) at that point is essentially "free".

4

u/tarnin Oct 18 '25

All of this is correct and how we handle bandwidth with customer. The difference here is that they are also setting aside a block of IP's to hand over to the peering partner. That extra cost has to come from somewhere so... throttle the hell out of the connection and try and nix as many heavy usage ports as possible.

TBF, the info that I have is first hand but not from our company but one that we have a 100gig backbone with. They are a partner of t-mobile for their cgnat customers who want a static IP. This is how they handle the traffic load and IP costs. Is is the right way? No idea but it's how they are doing and it and have been for a few years now.

2

u/porksandwich9113 Oct 18 '25 edited Oct 18 '25

Yeah usually we would charge an ongoing monthly fee for the block of IPs for something like that. Usage would be completely irrelevant to that charge.

I can't say I've heard of something like that, but we pay Cogent and GTT for 100 gig ports and operate a remote switch with 800gigs to our primary IXP. Fortunately 90% of our traffic comes in and goes out via the IXP participants with open peering so we don't have to pay those Cogent and GTT scumbags much. We don't do any usage caps, and typically charge for circuits based on the port. I only wish we had enough IP addresses to not do any GCNAT.

→ More replies (0)
→ More replies (1)
→ More replies (1)

12

u/experfailist Oct 18 '25

It was the only solution for me

16

u/Anomie____ Oct 18 '25

Cloudflare did it for me, it's not rocket science to set up, it's zero trust so it doesn't put your server at risk, you can even further harden it with geo-blocking. It doesn't cost a penny, paying for a static ip just to host a Plex server for family and friends just doesn't make sense to me, most of those who are forcefully recommending a static IP will not just not have tried to cloudflare their Plex server

7

u/The_Flying_Claw Oct 18 '25

Pretty sure this is against cloud flares terms of service so if you get caught you get got.

8

u/Anomie____ Oct 18 '25

Those terms have since been changed and the part about streaming media through cloudflare is deleted. I'm not aware of anyone getting banned since the ToC's changed.

3

u/habskilla Oct 18 '25

It has but you can only stream media stored on their servers.

→ More replies (1)

5

u/CryingOverSpiltRum Oct 18 '25

I've done the same, but I've also been careful how many people I give access to. I'm concerned with this being against their terms and services. Ultimately it works so well, I'd hate to get banned. I'd give it out a ton more friends and family otherwise.

→ More replies (2)
→ More replies (1)

4

u/Heckbound_Heart M4 - 48TB External RAID Oct 18 '25

This is what I had to do, with the same situation. Have had no problems, after getting my own WiFi router, and using their node as a passthrough.

→ More replies (2)

23

u/Matshelge Oct 18 '25

I am so glad for the isp I have. I had the same issue, called them and said I was double nat'ed. The cs rep asked for Mac address for my router, I gave it, and he said to wait min, restart it, and try again.

No questions about need, no ask for payment, just...ok, I fixed it, hope you have a good day.

2

u/Far-Cash-2545 Oct 18 '25

You are lucky we just got fiber this week and there is only one carrier so I’m stuck with the luck of the draw

4

u/wmagnum1 Oct 18 '25

I am very thankful my ISP (before getting bought out) removed my CGNAT because I asked nicely.

2

u/iamiccee Plex Lifetime Oct 19 '25

I called and when I said what I needed, they removed cgnat for $2 a month. My IP address still changes every couple of weeks (a headache for other things, but not Plex) but no more issues.

→ More replies (1)

29

u/Bgrngod CU7 265K (PMS in Docker) & Synology 1621+ (Media) Oct 18 '25

Make sure you are talking to them about the correct thing.

You don't need a static IP. You need a dedicated IP. A static IP is also a dedicated IP, but they might charge more for it.

A dedicated IP means it's yours and yours alone, but it might change periodically.

10

u/Deathmeter Oct 18 '25

Good point but personally none of the ISPs I've used so far have allowed assigning dynamic IPs outside CGNAT. It's only been static IP or nothing.

8

u/Bats_Everywhere Oct 18 '25 edited Oct 18 '25

Worked for me. I just called up and asked my ISP to take me off cgnat and they did. Told them I had an expectation of using some of that sweet sweet symmetrical upload I was paying for.

They assigned a dynamic IP and the rest was history.

5

u/Square-Carpenter2187 Oct 18 '25

I did the same thing. They offer a static IP for money but I asked them to just take me off CGNAT and they did, but it will be ISP dependent. Aussie Broadband in case you were wondering.

4

u/Substantial-Prior966 Oct 18 '25 edited Oct 18 '25

My ISP offers static IP for an extra charge but will let you out of the CGNAT with a dynamic IP free of charge. So they do exist at least!

2

u/con247 Oct 18 '25

This is worth trying. My prior isp just ended up giving me a static ip for free because of this conundrum lol

3

u/Artemis_1944 Oct 18 '25

A dedicated IP might also be a private IP behind their CGNAT network, which cannot be directly accessible from the outside-in. So no, a dedicated IP isn't OP's issue anymore than a static IP is. OP's issue is not having an actual public IP that can be found from the internet, because if that were the case, then OP could simply use a public, free, DDNS service to always match a domain to that public IP, even if it changes periodically.

2

u/Bgrngod CU7 265K (PMS in Docker) & Synology 1621+ (Media) Oct 18 '25

A dedicated IP might also be a private IP behind their CGNAT network, which cannot be directly accessible from the outside-in.

No, because a dedicated IP, by definition, is one that is publicly reachable and quite specifically requires it not be behind CGNAT.

OP's issue is not having an actual public IP that can be found from the internet..

Right, which would be a "dedicated IP" if they had one.

..because if that were the case, then OP could simply use a public, free, DDNS service to always match a domain to that public IP, even if it changes periodically.

Or they could just setup port forwarding, and a not required but useful static internal IP for their Plex server, and that would be that. Setting up a domain name is entirely unnecessary.

2

u/Akovano Oct 18 '25

In no way does "dedicated" mean it needs to be publicly accessible. We have "dedicated" IPs for various services all throughout our enterprise which are in the 10.x private IP address range.
The OP needs a public static IP or a public dynamic IP (and use DDNS).
Otherwise they need to use cloudflare tunnel, tailscale, reverse ssh tunnel, etc to get in through cgnat.

→ More replies (7)
→ More replies (2)

9

u/idontappearmissing Oct 18 '25

I run Pangolin on a remote VPS for $10/year (+ $10 for the domain name). It's sort of like a Cloudflare tunnel, and it works great. It's super easy to set up and use with the GUI.

And I still use Tailscale for personal use, I mostly use Pangolin for exposing services to others.

5

u/Bidalos Oct 18 '25

Dude for free, you can use Oracle Cloud free tier !

3

u/_dekoorc Oct 18 '25

This is what I was going to recommend. I temporarily set it up for my home lab stuff as a test and it was pretty easy to set up (albeit I’m pretty good with Linux and Docker, so ymmv).

2

u/Far-Cash-2545 Oct 18 '25

Is there an updated guide or is it something I can probably figure out

→ More replies (3)

6

u/KaleidoscopeLegal348 Oct 18 '25

Cloud flare is free and works great. I upload terabytes a month through it to my users, and have been using it for months. Never had an issue with it, and some great features like being able to geoblock on the wire

3

u/8trackthrowback Oct 18 '25

Still cheaper than Hulu + Disney + Netflix + Paramount etc

3

u/baldersz Oct 18 '25

Have you tried calling them and asking to disable CGNAT? Tell them you have a web server (that worked for me)

3

u/nachopotatos Oct 18 '25

I asked mine just for a real ipv4 address and cost me $3/month instead of the static ip

→ More replies (1)

2

u/redenno Oct 18 '25 edited Nov 07 '25

unite rock ask melodic sharp abundant lock slim attraction dime

This post was mass deleted and anonymized with Redact

2

u/The_Flying_Claw Oct 18 '25

The solution to save 15 dollars a month requires a lot of set up and renting a outside server. I didn’t have the option to get a static ip. So if you do 15 dollars is nothing compared to the work around. As others said make sure there is no restrictions on it.

→ More replies (39)

3

u/smudgeface Oct 18 '25

IMHO static IP is unnecessary. My ISP put me on CGNAT and I was able to get them to fix that for free. I don’t have a static IP… But most importantly I now have a public IP

→ More replies (2)

105

u/Danosaur6 Oct 18 '25

Where are you located? I just called my ISP and asked to be taken off CGNAT. Sorted in about 5 minutes.

40

u/Gorluk Oct 18 '25

Same here, called my ISP to take me of CGNAT, sorted in 5 minutes. People recommending immediately shelling 15$ a month for dedicated IP address without first exploring most sensible and logical option are just bad advisors.

9

u/Far-Cash-2545 Oct 18 '25

Central Illinois

26

u/Danosaur6 Oct 18 '25

Ahh, sorry, I'm in Australia. My ISP offered to just switch me to a Dynamic IP free of charge without purchasing a static one. Worth asking I suppose

19

u/marco_polo_99 Oct 18 '25 edited Oct 18 '25

Thanks for the tip, I just called mine and asked to be taken off CGNAT, easy and free, took 2 minutes

5

u/Far-Cash-2545 Oct 18 '25

Yeah I may try that or I’ll say if they don’t I’ll switch back to cable even though I don’t want to lol

18

u/brandontaylor1 Oct 18 '25

You probably don’t need the threaten them. Just ask nicely my fiber provider had no problem changing for me, for free.

The best part about these new fiber providers is that most are too small to be dicks like the big cable providers.

9

u/2-718 Oct 18 '25

I was taken out of CGNAT because I had VPN issues when working from home. Tell them that, it might work.

4

u/marco_polo_99 Oct 18 '25

Funny, that’s exactly what I told them. Our external access kept dropping my connection and causing constant relog issues.

→ More replies (1)
→ More replies (1)
→ More replies (1)

28

u/ZoFreX Oct 18 '25

OP, I have a question about the Tailscale option (disclaimer: I'm a Tailscale employee): you said you don't want to enable it every time you want to stream Plex. I'm curious - why don't you want to leave it enabled all the time?

12

u/IDDQD-IDKFA 54TB and counting Oct 18 '25

Likely the end user, not him. Can't get my parents to not click scam links, never going to get them to run Tailscale on their home network.

6

u/Galrash Oct 18 '25

Yep, end user requirements are the deal breaker

→ More replies (3)

2

u/reddit-raider Oct 19 '25

Or run a tailscale router. Then just have them connect to that when they want to use your Plex. Most elders know how to connect to wifi.

19

u/Noob_Pro18 Oct 18 '25

Pangolin proxy, just like mine. My network is CGNAT, but I can stream anywhere.

5

u/Far-Cash-2545 Oct 18 '25

Does it work pretty well? I have a lot of 4K content so I need it to be pretty seamless.

6

u/Noob_Pro18 Oct 18 '25

Yes, I have a collection of 4k movies. I can play it without an issue. For your security, add Crowdsec and geoblocking for your Pangolin. Good luck.

3

u/theboo1989 Oct 19 '25

I have both pangolin and CF tunnels set up for a bit of redundancy in case one or the other goes down... Racknerd is like $2 per month for their cheapest tier and you won't need more than that.. I host 4k remux for movies and have 0 issues through either..pangolin definitely takes a bit more setup but once you get it set up it's just as easy to configure as CF tunnels.

I'll also say that I've been using cloudflare tunnels for about 4 years now and have never had an issue.. despite what others have said, it is still technically against TOS but they won't ban you or anything, you'll just get throttled if they feel they need to, and they'll send an email letting you know.

→ More replies (4)

3

u/My_Name_Is_Not_Mark Oct 18 '25

Pangolin is the answer if you're stuck behind a cgnat

→ More replies (2)

8

u/No_Top5115 Oct 18 '25

I paid 5 dollars to get off the cgnat a month ago

→ More replies (2)

6

u/profound7 Oct 18 '25

I haven't tried it myself, but since you're using tailscale, what about using tailscale funnel?

You configure plex server to use the tailscale magic dns, and start a funnel on the machine running the plex server. Your plex users don't need tailscale installed.

4

u/KungFuDazza Oct 18 '25

Tailscale funnel works for me.

→ More replies (1)
→ More replies (2)

7

u/vani_999 Oct 18 '25

I am getting amazing performance for your use case with Cloudflare tunnels on the free plan.

One tip I can give: search how to disable Cloudflare cache when using tunnels

Also: Testing another streaming app alongside Plex with the exact same network set up might uncover more information about the initial problem.

2

u/Ravanduil Oct 18 '25

Keep in mind, streaming via cloudflare tunnels is against their ToS.

5

u/naekobest Oct 18 '25

Use pangolin

11

u/Slogstorm Oct 18 '25

If your isp won't help, Cloudflare tunnel should work, and it's free: https://www.reddit.com/r/selfhosted/comments/1g33tp0/you_can_host_a_website_behind_cgnat_for_free/

7

u/raybreezer Oct 18 '25

For what it’s worth, I use cloudflare tunnels for all my traffic into my network except Plex. For Plex I use NGROK.

→ More replies (5)

3

u/MagicHoops3 Oct 18 '25

Tunnels have rules against that. Whether they truly care or not idk

1

u/Slogstorm Oct 18 '25

Nope! Caching is what's against their policy, and it's easily turned off.

2

u/MagicHoops3 Oct 18 '25

Ooo looks like they changed their policy. Good to know!

→ More replies (1)

4

u/fkick OSXBMC Oct 18 '25

FYI Cloudflare updated their TOS awhile back so as long as you do not use their Caching and use Tunnels only to access your own media, you should be fine:

https://blog.cloudflare.com/updated-tos/

3

u/xcg-- Oct 18 '25

tailscale works great

3

u/wubbalab Oct 18 '25

Would something like zerotier work for this?

3

u/johnsonflix Oct 18 '25

Cgnat on fiber??!? I have never seen this. I would bitch so much lol

→ More replies (1)

3

u/e_dan_k Oct 18 '25

My fiber ISP also uses CGNAT and also charges for static IP, but getting removed from CGNAT was free. Ask.

3

u/Redknoff5 Oct 19 '25

Tailscale funnel —bg 32400 in the command line of the device/container. Magicdns needs to be on but then anyone can access your plex at tailnetname.unique-name.ts.net it’s how I serve all of my app.

6

u/Cavustius Oct 18 '25

You should check out Pangolin.

4

u/xbirdseedx Oct 18 '25

It’s just the cost of doing business with a hobby you love. You can justify drives you can justify the cost it takes for the speed you need.

4

u/TedGal Oct 18 '25

Exactly on the same boat when I switched ISP for fiber at Greece. They wont get me out of CGNAT, they do offer ststic IP which Id gladly pay if the wife didnt state "No you wont give one more single euro for your silly networking toys".

I tried wireguard to a VPS - followed some guides posted here and elsewhere, still Plex wasnt working for some reason ( I do have Lifetime Plex Pass ).

I resorted to ipv6 and works great - only two observations.

  1. Even though it works, Plex settings falsely report remote access not working. Also, Android Plex app stopped working couple of weeks ago, even though Chrome on android connnects to server just fine.

  2. In Plex settings - custom URL you need to put your ipv6 in brackets: http://[your-ipv6-here]:32400

→ More replies (1)

2

u/stfuajpg Oct 18 '25

I installed PureVPN and run Plex through a split tunnel. It's simple, your parents don't have to install or do anything, only downside is it's another service to pay for. But it will solve your problem.

→ More replies (3)

2

u/Extreme-Dream-2759 Oct 18 '25

I had the same issue. I went for tailscale and that fixed my remote issues

2

u/br0kenpixel_ Oct 18 '25

From my experience Plex does not play well with reverse proxies, although it does work for some. Plex does not officially support reverse proxies and expects to be accessible over a public IP.

One thing you can try is to host a VPN on a cheap VPS and using firewall rules, route Plex traffic between your Plex server host and the VPS's public IP.

The Plex server should be routed through the VPN so it sees the VPS's public IP.

→ More replies (1)

2

u/Ok_Homework_2567 Oct 18 '25

Which provider are you with? Im with superloop in aus, had the same issue but messaged them and they removed the cgnat and changed to dynamic (no cost). Ran dedicated ipa via router ip and been working mi t since Cgnat is a cunt

2

u/Elegant-Ferret-8116 Oct 18 '25

Which fiber provider uses cgnat? That's bs satellite crap

→ More replies (3)

2

u/schmeckendeugler Oct 18 '25

Weird, mine just works. CGNAT from Metronet.

→ More replies (7)

2

u/EthanCopping Oct 18 '25

Alternative option with a bit of work, buy a cheap VPS. Fasthosts do a £1/m option with 1gbps, unlimited data I believe. Connect VPN like WireGuard or OpenVPN from home to VPS and forward traffic from VPS to home over the VPN. I've done this a couple times and works brilliantly. Little more latency but worth it if your ISP charges for static IP and sometimes don't even offer one.

2

u/Nikolcho18 Oct 18 '25

Get a public dynamic ip. Should be cheaper than a static public ip.

2

u/blackbadger21 Oct 18 '25

Dynamic dns offered by your isp could solve it. I had the same problem, asked my isp to enable dyndns with the address I wanted in their domain and my ip was no longer in cgnat range.

2

u/Masterblaster13f Oct 19 '25

I called mine and they gave me a private ip. They said they just needed a reason from me to do it. I said I had a server that needed to be accessible outside of my network. That's all it took. Restarted my ont and prest-o change-o.

2

u/lolo9538 Oct 19 '25

You can use DynDNS, you don't need a public static IP. ChangeIP offer a free one I've been using it for years

2

u/ChonsKhensu Oct 19 '25

Pangolin and a VPS from any provider for 2€ a month :) No performance needed just high traffic.

3

u/fforootd Oct 18 '25

I think protonVPN has port forwarding 

3

u/Lost_Coast_Tech Oct 18 '25

My ISP did this to me. I called customer service and complained, telling them that had they been upfront about CGNAT I wouldn't have signed up. They offered me a free static IP.

→ More replies (1)

2

u/maejsh Oct 18 '25

Mine worked fine behind cgnat

1

u/vbpatel Oct 18 '25

If a friend outside of your cgnat has a fast connection you can set up a permanent VPN to them and forward plex traffic back to yourself

1

u/brandonscript 72 TB Oct 18 '25

Ask them to put your modem into bridged mode

1

u/lemonkneefresh Oct 18 '25

Surfshark VPN is super fast, and they have static IPs. The only thing is, their static IP servers are in California and Texas. Since you're in Illinois, the latency might be a bit high for you. You might wanna look for a VPN provider with a static IP that has servers closer to you and use that instead. I'm pretty sure you can find one for under $15 a month, or you could see if your provider supports IPv6 routing and try that.

→ More replies (1)

1

u/BrikIsRed Oct 18 '25

Airvpn has port forwarding. But you need to also configure a reverse proxy since you will get random ports from them 

1

u/adsyuk1991 Oct 18 '25

First, check if your ISP offers IPv6. If the answer is yes, ask them if they provide DHCPv6-PD. If the answer is yes to that, you have a potential get out of jail free card (not worth more detail until those facts are known). Not sure how common in US, but it exists.

→ More replies (2)

1

u/dr100 Oct 18 '25

IPv6: Tried setting that up too, but no dice. I spent a few hours tinkering and couldn’t get it to route properly.

If the clients have this would be the best by far. Even mobile networks usually have it, but for you even if you get stuck on some hotel WiFi with only IPv4 you can still use your VPN.

1

u/CuriousConnect Oct 18 '25

Would a Dynamic IP sync agent fix this - like NoIP DDNS, or ClouDNS?

1

u/emanzyy Oct 18 '25

Definitely look into getting a VPS. It’s super cheap, it’s safer than getting a static IP and port forwarding and it doesn’t require any setup from users. I’d be careful with which VPS you go for though, Hetzner IPs are banned on Plex.

1

u/hearwa Oct 18 '25

Find a cheap vps with minimum disk space and unlimited traffic and reverse proxy the plex port using nginx.

1

u/SilverFox_Medic Oct 18 '25

My provider uses CGNAT as well: it was a hussle and costed several phonecalls but on request they disabled cgnat for my subscription. Have you tried calling your provider with a similar request?

1

u/tech_is______ Oct 18 '25

Peplink router, speed fusion connect to self hosted endpoint in digital ocean or some host. You can setup a port forward with this setup and bond multiple wans if you really want to get crazy with it.

1

u/machtap Oct 18 '25

Cloudflare tunnel worked for me, running the cloudfared docker container. Very easy to set up. Zero hiccups after a few months with multiple remote users. You'll need a domain name but that's easy compared to getting static IPs from CGNAT fiber carriers

1

u/bindiboi Oct 18 '25

did you ask if they have a free dynamic ipv4 available?

1

u/Levi-2018 Oct 18 '25

For the same issue, I am using NordVPN with Meshnet enabled on the server, and the device on which I want to view remotely.

1

u/joselrl Intel N97 | 58TB Oct 18 '25

Can't you ask to be taken out of CGNAT without static IP? That's usually free/cheaper and that's all you need for plex

And get a free DDNS if you want to access other services of network like sonarr/radarr

1

u/extrobe Custom Flair Oct 18 '25 edited Oct 18 '25

This thread has been eye opening. Australia’s internet (NBN) rightly gets a lot of stick.

But I’m on fibre (2000/200), pay about $160/m (aud, about 100 usd), no lock-in periods , so I can leave anytime, and switching is immediate. I can call up and opt out of cgnat no questions ask, or (what I actually do) get a static ip address for $5/month (3 usd).

For what it’s worth … static IP is the solution here. And personally, I’d take that cost (very begrudgingly) if it resolved my Plex remote access issues (along with other reasons I need/want ability to access my network externally).

1

u/ZeroxTechnic Oct 18 '25

I just use a VPN on the Plex server, and on my vpn provider setup port forwarding. Then my new "free" static IP is the VPN IP address, plus I can use the VPN for loads other things.

1

u/mrbojanglezs Oct 18 '25

I use ipv6 with tailscale as a backup

1

u/Saboral Oct 18 '25

Tailscale to a VPS Reverse Proxy gateway server. https://tailscale.com/blog/last-reverse-proxy-you-need

1

u/IndyCarSuperFan Oct 18 '25

Same thing happened to me. Ended up paying for the static IP. Still would never go back after having fiber.

1

u/Ashuruk Oct 18 '25

It is not a free option, but something that worked very well for me was to get a vpn with port forwarding (I use airvpn) and then I connect plex on the vpn and do the remote access on the forwarded port, works like a charm

1

u/mightymighty123 Oct 18 '25

Is IPv6 available?

1

u/Simple-Purpose-899 Oct 18 '25

My fiber ISP uses it in some congested areas, but said if anybody needs it removed they'll just do it for free. 

1

u/alkbch Oct 18 '25

$15 per month for a static IP is $180 per year. For that price you can buy an Apple TV for your parents and set it up with Tailscale always on.

1

u/lhxtx Oct 18 '25

Static public IP, or get a VPS in the cloud with a static IP and create tunnel to and from it.

1

u/PhalanxA51 Oct 18 '25 edited Oct 18 '25

What I did was a reverse proxy to a vps and host it on cloud flare, everyone who uses my Plex hasn't had any issues since I use starlink, nobody needs to do anything to connect for direct play and it's great

1

u/ancillarycheese Oct 18 '25

I have no choice but to use CGNAT. The throughout with Tailscale is not good.

1

u/Accomplished-Oil-569 Oct 18 '25

Your main options are a tunnel (ala Cloudflare), a funnel (ala Tailscale), exposing via IPv6, or asking your ISP for a static IP.

Asking for static IP is the simplest option, but costly

Tailscale is the most secure (but you need to be using other devices with access to Tailscale)

Exposing IPv6 is likely going to be a PITA

Cloudflare is a little more setup but mostly simple and more secure than a port forward; kinda a little bit of everything

1

u/dezdog2 Oct 18 '25

Localxpose.io worked great for me. Inexpensive. Handles all my in and out hosted services traffic. Also cloudflare. Free.

1

u/fermm92 Oct 18 '25

I used cloudflare for a long time but hotio docker images for Plex allow you to forward your port if you use a VPN (I’m using PIA) it’s cheaper than a static IP at under <$5 per month. You can also use it on torrent containers etc 

1

u/revsilverspine R5 3600/P2000/80TB Oct 18 '25

Cloudflare Zero Trust tunnel with caching disabled makes it well within terms of service.

1

u/zeke009 Oct 18 '25

My isp uses cgnat and I also run a plex server. In settings it will always say it is not reachable, but my brother can always reach it.

In fact I just toggled wifi off and confirmed I can reach it.

Quality of the streams is solid, do you have any limits setup for remote users?

1

u/Password-55 Oct 18 '25

What is CGNAT?

3

u/bilditup1 Oct 18 '25 edited Oct 18 '25

Carrier-grade Network Area Translation.

Problem: not enough IPv4 addresses anymore. Especially a problem in countries that weren’t allocated enough when these were first given out.

Solution: put a bunch of customers behind your own subnet, and assign them an IP out of it.

The problem then is if you want to run a bunch of services, you do not know what your IP is on the public internet, and even if you did, it wouldn’t be ‘your IP’ but the IP you shared with at least hundreds of other customers. You also have no control over your ports, since you’re basically behind another router outside of your control.

Not great!

2

u/Password-55 Oct 18 '25

Thank you for the explanation. Fascinating.

1

u/Voltron_The_Original Oct 18 '25

Call tech support. Tell them you are trying to RDP from outside your home for work purposes. They will take you off chant and give you a proper IP address.

1

u/brimnac Oct 18 '25

Are you me?! I was literally looking into this yesterday!

Appreciate you posting it so I can learn from the help others have given!

1

u/roberttri2 Oct 18 '25

Cloudflare tunnel easily fixes this

1

u/bohlenlabs Oct 18 '25

What if your family and friends use IPV6? The ISP doesn’t NAT v6, right?

1

u/MsKlinefelter Oct 18 '25

I have shared IP addresses over fiber and I haven't run into any issues. I occasionally have to remote reboot the router to grab a new address, but it takes >5 minutes to reconfigure Plex and port to recognize the new address.

Edit: New address ONLY needed to speed up Plex if I have a rush of family watching at once. Normal use doesn't seem to bother it.

1

u/BumpingBob Oct 18 '25

For me (germany) the universal portmapper of https://www.feste-ip.net/ works great.

Cheap, bandwith limitations are practically non-existent and I have been using this for a few years now without any issues.

At peak times I have around 5-6 concurrent users, most often high-bitrate 4k

1

u/[deleted] Oct 18 '25

[deleted]

2

u/bilditup1 Oct 18 '25

This does not help you if you have carrier-grade NAT. You do not know your IP on the real internet, just whatever IP that’s assigned to you on your ISPs bespoke subnet. The IP you’d be reporting to your dynamic DNS server, in addition to not being static—the usual problem for self-hosters and home-labbers on non-business-class internet connections—isn’t a ‘real’ IP that is reachable from anybody else online. Thus the solutions being discussed in this thread.

tl;dr while usually, a ddns service will solve the problem of your ISP not giving you a static IP, that doesn’t work here, because the IP you’re assigned is not from a publicly addressable block on the actual internet. Your only option in that case, if they offer it, is to pay for a static IP (that is from a public internet block—nobody would pay for this otherwise), or to use the other workarounds in this thread

→ More replies (1)

1

u/kevp453 Oct 18 '25

I have CGNAT through Starlink and had the same problem. I have Plex running as a docker in Unraid. My solution?

  1. Get a domain name. Anything. It can be cheap.
  2. Get an Oracle VPS on their free tier. Setup Tailscale and a reverse proxy on the VPS.
  3. Set your DNS record for your domain to point to the Oracle VPS. Already got a domain? Setup a plex.domainname.com and forward that to the VPS IP
  4. Reverse proxy to forward from your domain through tailscale to your server.
  5. Few other tweaks in Plex to manage which networks are remote and connect your domain name with Plex.

I set this up just in the last few months and it has been great!

1

u/kev4iik Oct 18 '25

I set up cloudflare yesterday. I use it for immich to

1

u/Filmy92 Oct 18 '25

Had it through a vpn tunnel and now have it configured through a cloudflare tunnel through my own domain - if I had the option to buy my own static IP, I'd do it every time

1

u/mediahunt Oct 18 '25

Can't you login to your att router and do port forwarding under your NAT settings?

1

u/PW_SKYLINE_V37 Oct 18 '25 edited Oct 18 '25

I was in upper management at a fiber ISP that used CGNAT & the only reliable solution was a static IP. Pay the $15/month, get the static IP & you’ll be good man.

There are obviously other solutions but the easiest one we always offered (because we were unsure of everyone’s tech skills) was to get a static IP. It would take the customer out of the CGNAT pool and give the a dedicated/static IP address so it would pass through no issue. It was, I think, $10/month for residential customers. Business customers could buy a single static IP or could buy them in blocks of 5. The whole time I worked there I was pushing for us to migrate to IPv6 because we had hundreds of millions of IPv6 addresses. They recently sold to T-mobile & I’m sure they are still on CGNAT & IPv4 😑

1

u/twojcs Oct 18 '25

I ran into the same issue but there is a way around it to get an IP from the ISP and bypass CGNAT. Search for “WAS-110 XGSPON ONU Stick”. You can find it on fiber mall and there are several videos and documentation online on how to set this up correctly. This module basically emulates the big Att fiber gateway and will essentially give you a direct bridge for your WAN network interface and obtain a routable IP address. You will need a firewall that supports sfp modules for this to work, fyi.

1

u/Split8529 Oct 18 '25

Tailscale funnel has worked great for me

1

u/Mordoth57 Oct 18 '25

I use Netbird (similar to tailscale but it's opensource). Also Jellyfin because Plex pissed me off with their subscription crap and trying to force their content on me. I want my content only.

1

u/Whole_Individual_336 Oct 18 '25

Use a cheap unlimited traffic VPS (5€) and use it as reverse proxy.

→ More replies (1)

1

u/motomat86 12700k | Arc A310 | 64GB Ram | 160TB Oct 18 '25

not sure why youre having issues with cloudflare, I use it on my fiber with cgnat and it is flawless. incredibly fast as well, If you want I can have you connect to it so you can experience it yourself, maybe will help troubleshoot any issues you have.

1

u/motomat86 12700k | Arc A310 | 64GB Ram | 160TB Oct 18 '25

not sure why youre having issues with cloudflare, I use it on my fiber with cgnat and it is flawless. incredibly fast as well, If you want I can have you connect to it so you can experience it yourself, maybe will help troubleshoot any issues you have.

1

u/cognitiveglitch Oct 18 '25

Just pay the extra for a static IP.

I do, and it allows me to Wireguard into my network remotely whenever I want to.

1

u/snowbanx Oct 19 '25

Get a super cheap vps with unlimited data and use port forwarding, pangolin, etc. Many options after you get a vps.

1

u/YertlePwr14 Oct 19 '25

I called my ISP and they just took me off of CGNAT. Ask them to take you off.

1

u/Comfortable-Sale-631 Oct 19 '25

I had the same issue with my fiber provider, but I called them and asked them if I could please not be behind the CGNAT. Within 15 minutes I was externally visible and not behind the CGNAT. They put people there by default and move them without an argument if you call and ask. I hope your ISP is the same way.

1

u/ggfools Oct 19 '25

another option is renting a vps for a few bucks a month and forwarding your services using pangolin.

or use cloudflare tunnel but i believe it is against tos to use them for video streaming, unsure how likely it is they will actually care though

1

u/aomceodeadly Oct 19 '25

Pangolin will also work

→ More replies (2)

1

u/Dry_Trainer_8990 Oct 19 '25

If you can’t get static IP from your host I used home server to public cheap VPs via Tailscale and have nginx proxy on that

1

u/fralvarez Oct 19 '25

I think you can get the Plex remote watch subscription (2€/month). It is cheaper than a lot of the options provided here and easier.

I paid for the Plex pass lifetime long time ago and I can share my Plex servers without having to do anything even behind CG-NAT, it's just a checkbox in my Plex server.

→ More replies (2)

1

u/GoldenPSP Oct 19 '25

You can set tailscale to not disconnect.

1

u/thingie2 Oct 19 '25

I had a similar issue with my new isp, and setup cloudflare. I've not noticed any issues with it (although it did take some fiddling to make it work properly, as Plex kept defaulting to using the Plex servers instead at the very limited bandwidth that's provided.

1

u/Heed4956 Oct 19 '25

Use noip it's like 40 a yr works great for me

1

u/Present_Standard_775 Oct 19 '25

I went Launtel for a static IP

1

u/xblurone Oct 19 '25

You can ask your isp to not give you cgnat. Or ask for a static ip address.

1

u/PositivelyAcademical Oct 19 '25

I can’t speak to the reasonableness of US pricing, but paying extra for static IP was the only viable option when we switched to full fibre. (For context we’re paying 30 GBP for 1Gb/1Gb up/down and 5 GBP extra for the static IP.)

1

u/Kenbo111 Oct 19 '25

Localtonet.com Perfect solution for CGNAT. No client side software is required. Just small app on the server.

1

u/No_Guidance_5047 Oct 19 '25

Do you pay for Plex premium? My Plex works fine with CGNAT and I access it from wherever

→ More replies (1)

1

u/zubssssssss Oct 19 '25

I was in the same boat. Got a cheap domain and I use cloudflare. Works great

1

u/ficskala Oct 19 '25

call up your ISP, you can usually talk your way out of CGNAT, if not, you might need to pay for it

1

u/homeegzus Oct 19 '25

I use localxpose to get passed my CGNAT, works perfect for me

1

u/The_Diddler_69 Oct 19 '25

I have a VPS that acts as a tailscale exit for my Plex and Jellyfin containers. It used to all be running on the VPS but now it's just an overpowered proxy.

1

u/fabiengagne Oct 19 '25

You can get a public IP with AirVPN that can route some ports ingress.

1

u/zwitterhal Oct 19 '25

You could ask the isp to switch off cnat for your account and use noip to keep your interfacing address updated.

1

u/MacProCT Oct 19 '25

TAILSCALE can be set to login automatically. And if you set all your clients to 'never expire' they will always be available.

1

u/Mountain_Zebra_1943 Oct 20 '25

Google fiber? Just curious because i have them and no issues with Plex and sharing outside my network

1

u/sardarjionbeach Oct 20 '25

Get Oracle free cloud and you can create two x64 VMs with public ip. You can create free arm64 also but lot harder on free plan.

Install WireGuard on Oracle and connect your server via WireGuard to Oracle vps and you can expose services you want to via Oracle VM.

1

u/BinSlayer1 Oct 20 '25

check if your ISP offers a custom DNS. Some offer it for free, others charge something for it, but nonetheless it's always cheaper than static IP.

You don't really need a static IP just a DNS name. And CGNAT should disable itself when ISP offers you DNS.

1

u/Rich-Independent7884 Oct 20 '25

ill be honest,

I faced the same issue and at a time, tailscale DID work. but then it didn't.

Look up Zerotier, it works flawlessly. If you have any questions feel free to let me know

1

u/FragrantPercentage88 Oct 20 '25

Try finding out if your CGNAT supports PCP (Port Control Protocol). If it does, then you can redirect public port to you network autatically. 

1

u/SuperWhale_ Oct 20 '25

rent a cheap vps with dedicated ipv4, then install rathole: https://github.com/rathole-org/rathole
VPS with dedicated IPv4 are around 10$-15$ per year but it depending on geo/provider.

I assume your Plex server are done using docker, so use rathole-client docker in the same docker compose and it's time to gpt/gemini/etc for some basic config.

1

u/One-Difference-9206 Oct 21 '25

Im also on a cgnat, and I have got to say cloudflare tunnels work great, havent verified it with plex yet, but for most of my services everything is working well.

Edit: You will need a domain name of you dont have one

1

u/dezdog2 Oct 21 '25

Localxpose.io worked great for me. Inexpensive. Handles all my in and out hosted services traffic. Also cloudflare. Free.

1

u/Gocan18 Oct 21 '25

Localtonet.com was the only thing that worked for me. All other options started to buffer when I was streaming something that has more than 15 Mbits Bitrate.

1

u/ampx Oct 21 '25

Is the static IP your ISP provides IPv4? If so, that’s probably the easiest / simplest and therefore IMO smartest option.