Documentation
Forward ports on your router
Open ports 80 and 443 to the machine running your watch party — find your router's settings, add the two forwards, check they work, and what to do when your provider blocks them.
Your watch party runs on your own machine. Members open it in their browsers at your web address, so your router has to pass that traffic through to the machine. That is a port forward: a rule on your router that says "anything arriving on this port goes to that computer".
The watch party needs two. A game server needs one of its own, and Plex needs one only if you want its own apps away from home.
What ports 80 and 443 are for
| port | what uses it |
|---|---|
| 443 (TCP) | Members' browsers. Every watch-party page and stream is served here, over HTTPS |
| 80 (TCP) | Getting and renewing your address's certificate, and sending anyone who types http:// on to https:// |
Both go to the machine running the watch party, on the same port at both ends: 80 to 80, and 443 to 443. Nothing else on that machine is opened — the projector and the stream listen only on the machine itself, behind the watch party's own web server.
Before you start
- A web address that points at your home connection. A free one from DuckDNS works; the Open the screening room step of /menu › Other › Admin › Media › Set up saves it with Set address. Media server setup walks through the whole step.
- The machine's address on your own network — the one that starts
192.168.,10.or172.:- Windows: run
ipconfigand read IPv4 Address. - macOS: System Settings › Network, pick your connection, Details, and read IP address.
- Linux: run
hostname -I.
- Windows: run
- A reservation for that address. Routers hand addresses out afresh from time to time. Most call the fix a DHCP reservation or address reservation: give the machine one, or the forward will one day point at nothing.
Find your router's settings page
Its address is your network's default gateway:
- Windows:
ipconfig, the Default Gateway line. - macOS: System Settings › Network › Details › TCP/IP, the Router line.
- Linux:
ip route, the address afterdefault via.
It is usually 192.168.0.1, 192.168.1.1 or 10.0.0.1. Open it in a browser and sign in — the
password is often on a sticker on the router. Some providers' routers are managed only through the
provider's own app instead.
Add the two forwards
Look for a page called Port Forwarding, Virtual Server, NAT, Port Mapping or Applications & Gaming, and add two rules:
| name | external port | internal port | protocol | send to |
|---|---|---|---|---|
| watch-https | 443 | 443 | TCP | the machine running the watch party |
| watch-http | 80 | 80 | TCP | the same machine |
Save, and apply or restart if the router asks. If the machine runs a firewall of its own, allow ports 80 and 443 in there too.
Where the setting usually lives — names move between models and firmware, so treat these as a place to start looking:
| router | where to look |
|---|---|
| TP-Link | Advanced › NAT Forwarding › Virtual Servers |
| NETGEAR | Advanced › Advanced Setup › Port Forwarding / Port Triggering |
| ASUS | WAN › Virtual Server / Port Forwarding |
| Linksys | Security › Apps and Gaming › Single Port Forwarding |
| eero | the eero app: Settings › Network settings › Reservations & port forwarding |
| Google Nest Wifi | the Google Home app: Wi-Fi › Network settings › Advanced networking › Port management |
Check it worked
Open your address on a phone with Wi-Fi turned off, so it comes in from outside the way a
member's does. A page that loads over https:// means both forwards work.
⚠ A test from inside your own house can fail even when the forwards are right: many routers will not loop your own public address back to you. Test from outside.
When it does not work
Two routers. If your provider's box is a router too and yours sits behind it, the traffic stops at the first one. Put the provider's box in bridge mode (sometimes called "modem only"), or forward 80 and 443 on both — on the provider's box to your router, and on your router to the machine.
Carrier-grade NAT (CGNAT). Some providers share one public address between many homes, and then
no forward on your router can work. Compare the WAN or Internet address on your router's
status page with the address DuckDNS shows you: if they differ, or the router's is between
100.64.0.0 and 100.127.255.255, you are behind CGNAT. Ask your provider for a public IPv4
address — many give one on request, some charge for it, and some only offer it on business plans.
Your provider blocks port 80. Some home plans do. The certificate can usually still be issued over port 443 alone, and members only ever use 443, so forward 443 and try again.
Your provider blocks port 443. Rare, and the watch party has to be reached on 443 — members open your address with no port in it. Ask your provider to lift the block, or move to a plan that allows it.
The router uses 80 or 443 itself. Some routers refuse a forward on a port their own remote management (or "remote access", "web access from WAN") uses. Turn that off, or move it to another port.
It worked, then stopped. The machine's address changed — give it a reservation (above) and fix the forward — or your home's public address changed and your web address still points at the old one. Update it wherever you made the address.
Game servers
The same steps, with the game's own port. Each game uses its own — Minecraft Java Edition uses 25565 (TCP), and many Steam games use UDP ports. /menu › Other › Admin › Game Servers › Setup › Set up shows the port recorded for each server, and its How members connect step tests it from outside your house, the way a member reaches it.
A private network (a tailnet) is the other way to let members in, with no port opened at all; the same step asks which you want. See Game server setup.
Plex remote access (optional)
Watch parties do not need Plex open to the internet: your machine reads Plex on your own network, and members watch through the watch party. Open it only if you want Plex's own apps to reach your library away from home.
In Plex, turn on Settings › Remote Access. It asks your router to open port 32400 by itself (UPnP). If it says it cannot, forward 32400 (TCP) to the computer running Plex, the same way as above.
Further reading
- Plex's own guide to Remote Access.
- portforward.com keeps step-by-step screenshots for thousands of router models.
