Install the app
How to install the app on iOS

Follow along with the video below to see how to install our site as a web app on your home screen.

Note: This feature may not be available in some browsers.

NAS but also Mac Mini

829
258
NAS
DS918+
Operating system
  1. macOS
Mobile operating system
  1. iOS
I've given up running JellyFin on the NAS as it (as well as Plex) just eat too much CPU / Memory.

An easy solution is to set up JellyFin on my Old Mac Mini. It works well, but the problem is getting access to it from the real world. I'm following this guide.

The Orbi router has been set to Forward Port 8096 to the Mac Mini
The DNS entry has been set to go to the DDNS name of the Orbr router, that is updated via th No-Ip DDNS app on the Mac Mini.

So this should work, but it doesn't, as I get SSL certificate errors. Guys on the Cloudflare forum have suggested I turn off HTTPS (which I don't want to do).
The tutorial (above) suggests using Caddy (which looks very complex) for DDNS, but I can't do that as it wants ports 443 & 80 forwarded to it and of course they are forwarded to the NAS.
So I think I'm stuck - The Cloudflare DNS seems like it needs to go through the NAS, but the NAS can't (as far as I can see), link to the Mac Mini.

Does it make sense what I'm trying to do? If so anyone any ideas as to how to achieve it?
 
Last edited:
Why can't you use the DSM reverse proxy to land the external requests. Then direct to the Mac Mini’s Plex server. The HTTPS and certificate would then be handled by the NAS. The Mac will still do the processing load.
 
The easiest would be to set all reverse proxy rules on NAS itself as @fredbert already suggested above.
Next step is to run Nginx Proxy Manager in a docker container (your DS918+ supports it) and let it handle proxy rules and certificates. This is what I prefer.
 
While I don't know how JellyFin does it, in Plex server there is a customer server access URL you can define so that this is what Plex.tv tells users to connect to for direct access. That's if it is different to the port you set for the service to listen on listening.

The way I would proceed is this:
  1. What is the JF/Plex server configured to enable connectivity?
  2. What does the router see at the JF/Plex server?
  3. What does Cloudflare see at your Internet router when it wants to access the JF/Plex server?
  4. What does the client device on the Internet see at Cloudflare when it wants to access the JF/Plex server?
There is no one direct connection from the client to server, it goes through the above steps and each needs to be correct.

So assuming the security is all being done, by way of SSL certificates, by Cloudflare then you might consider the JF/Plex server as secured... provided there is no way to side-step Cloudflare using a different FQDN/IP address. This was my reason to use DSM's reverse proxy, to have an internal point where HTTPS on my certificates are processing my Plex server's external access. I then proxy to the DSM hosted Plex server. But there's not reason I couldn't host the Plex server on another LAN device and just change the reverse proxy rule.

Are you sure that the loading is being done by the reverse proxy, and not the JF/Plex server itself on the NAS?
 
Last edited:
The local access is using HTTP or HTTPS? And if HTTPS, is there a similar connection warning?

The Vivaldi warning is about the SSL certificate being mis-matched to the FQDN you have used to access the JellyFin server. So the JellyFin in your setup looks like it should be providing the SSL certificate, because CloudFlare is set to DNS and not Proxy the resolution. I'm guessing that CloudFlare would provide a proxy for inbound requests, and that this proxy will handle incoming HTTPS requests with suitable certificate. That the onward connection to the JellyFin server could then be a HTTP request (or unvalidated HTTPS).

Addnl... a web search for 'cloudflare dns-only vs proxied' provides information on these two options. With dns-only it appears that the DNS request is replied with the resolution, like normal DNS. With proxied then the request is handled with CloudFlare's reverse proxy, with other security features. The next thing to then ensure is that only requests from CloudFlare proxy are permitted by JellyFin (to avoid bypassing it)... and I saw there was a server setting that could be used to assign only the allowed sources.
 
Not sure that you need NPM in the current instance.

If you have configured DSM reverse proxy to listen for HTTPS using your JF FQDN on port 8920, then the router just has to forward 8920 TCP to the NAS LAN IP. The reverse proxy then sends to the Mac MIni's LAN IP on the JF HTTP or HTTPS port.

Now in DSM's Control Panel you can assign the right SSL certificate to this JF FQDN:port. Just look for the assignment under Certificate page's Settings button.
 
Last edited:
The solution
  • Orbi router - JellyFin HTTP & HTTPS ports forwarded to NAS
  • Reverse proxy on NAS port HTTPS sends to HTTP on Mac mini
  • Reverse Proxy Certificate settings - Cloudflare Origin cert set
  • Set DNS on Cloudflare to point at Proxied QuickConnect
  • Cloudflare rule set to change the plain URL (no port) to the HTTPS port
  • Open JellyFin HTTP & HTTPS firewall ports on the NAS
Working nicely :)
 
I don't know what you have achieved so far, but your links above point to your Jellyfin instance! You should hide them...
 
Good idea, all done, I think. My posts in the thread sanitised. :)

My greatest thanks (as always) to everyone for the assistance.
 
My only comment would be this: I don’t see why the Orbi router needs to forward the JF HTTP port to the NAS, or anywhere, if there’s not going to be any external access using HTTP.

First test would be to block the HTTP port access in the NAS firewall. If things stop working then you need it. If things still work then you can remove the rule and the port forward.

Unless the CloudFlare proxy needs you to load its certificate in to DSM, you might not need this step. It all depends if CloudFlare tests the validity of the certificate on the server that it makes its connection. If it is needed then you’ll have to remember to export/import this certificate as it gets renewed.
 
Good call, the HTTP port has indeed been removed from the router and the NAS and all is still working. The certificate lasts for 3 months and is automatically renewed by Cloudflare.

The JellyFin apps have been added to mobile devices and the LG TV with no issues at all.

Job completed I guess. :)
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Similar threads

There had been a lot of posts lately concerning remote access to the NAS when hosting Pi-Hole on the NAS...
Replies
0
Views
637
  • Question Question
SMB2/SMB3. SMB1 is insecure and highly susceptible to malware. DO NOT ALLOW SMB1 anywhere.
Replies
3
Views
265
  • Question Question
Hi, On my Synology RS 3618xs I suddenly ran into problem concerning NFS directory mount. When I mount a...
Replies
0
Views
179
It's relatively straightforward. SSH into your Synology and run below command as root user. sudo...
Replies
4
Views
3,376
  • Question Question
Similar install here, (1 NAS connected to router, other NAS’s via switch), but no connection issues ever...
Replies
4
Views
593
I realize this thread is old. I haven't been here in a while. Here's what I did for anyone else reading...
Replies
51
Views
15,834

Thread Tags

Welcome to SynoForum.com!

SynoForum.com is an unofficial Synology forum for NAS owners and enthusiasts.

Registration is free, easy and fast!

Trending content in this forum

Back
Top