<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>DNS Rebinding - Plex</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/148013/dns-rebinding---plex</link><description>I’m in the process of getting Sophos XG Home as an alternative to pfsense. 
 I’m 90% there, but is there a way to do DNS Rebinding, particularly for plex? 
 i don’t want to open ports as I accessed everything via a VPN with pfsense and it worked perfectly</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: DNS Rebinding - Plex</title><link>https://community.sophos.com/thread/548778?ContentTypeID=1</link><pubDate>Mon, 18 Nov 2024 15:03:25 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:3e4b1844-61b9-439f-b8ab-baa50645c76f</guid><dc:creator>MikeyS</dc:creator><description>&lt;p&gt;Apologies, I prob describe it poorly.&amp;nbsp; Effectly it&amp;#39;s off the back of this artice from plex.&amp;nbsp;&amp;nbsp;&lt;a href="https://support.plex.tv/articles/206225077-how-to-use-secure-server-connections/"&gt;How to Use Secure Server Connections | Plex Support&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Withing that article it describes workarounds:&lt;/p&gt;
&lt;p&gt;&amp;quot;dnsmasq&lt;br /&gt;To allow secure connections to work correctly on the local network if you are using &amp;ldquo;dnsmasq&amp;rdquo; with DNS rebinding protection enabled, you will need to add the following line to your configuration file (the &amp;ldquo;advanced settings&amp;rdquo; box in DD-WRT):&lt;/p&gt;
&lt;p&gt;rebind-domain-ok=/plex.direct/&lt;br /&gt;Related Page: Manpage for Dnsmasq&lt;/p&gt;
&lt;p&gt;pfSense DNS Resolver&lt;br /&gt;Similarly, if you are using pfSense&amp;rsquo;s internal DNS resolver service (specifically the &amp;ldquo;ISC DNS&amp;rdquo; resolver), you&amp;rsquo;ll want to adjust that configuration. In the pfSense web UI, go to Services &amp;gt; DNS Resolver, click Display Custom Options, and enter the following the the text box:&lt;/p&gt;
&lt;p&gt;server:&lt;br /&gt;private-domain: &amp;quot;plex.direct&amp;quot;&lt;br /&gt;Related Page: pfSense: DNS Rebinding Protections&lt;/p&gt;
&lt;p&gt;Remote Access Workaround&lt;br /&gt;In some cases, it may be possible to work around DNS rebinding protection by enabling Remote Access for your server. When enabled, this allows connections to be made via your public/WAN address. In most cases, your router will automatically keep such connections within your LAN, though this isn&amp;rsquo;t universal across all routers.&lt;/p&gt;
&lt;p&gt;Warning: When working around DNS rebinding protection this way, your apps and Plex Media Server will typically treat the connections as being from a &amp;ldquo;Remote&amp;rdquo; source. This can affect which streaming qualities are used, as well as trigger Remote-applicable server bandwidth and transcoding limitations.&amp;quot;&lt;/p&gt;
&lt;p&gt;At present I have exposed Plex via port forwarding on the WAN interface and that works fine, but prefer not to port forward.&lt;/p&gt;
&lt;p&gt;I was going to have a look at WAF, but I&amp;#39;m not sure if that&amp;#39;s geared for applications like Plex etc.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: DNS Rebinding - Plex</title><link>https://community.sophos.com/thread/548728?ContentTypeID=1</link><pubDate>Sun, 17 Nov 2024 14:16:40 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:84d6169b-5cb9-41df-b00e-ccd924853f23</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;Can you give some more context on what you want to do? Because DNS rebinding is more an attack scenario to me than a feature.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>