Assuming the user will not be connecting over vpn, but is both remote and non-technical, how would you expose Jellyfin to them securely?

you are viewing a single comment's thread
view the rest of the comments
[–] 5 points 3 months ago (1 child)

Also not as ideal if their ISP uses CGNAT. Still waaay better than fully open, but you would be giving access to many households

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 3 months ago*

    Yep, that's why I call that a tradeoff. Far from perfect and yet so much better than nothing.

    Pros:

    • Likely cuts 99.99% of attacks.
    • Nothing to do on client's end.

    Cons:

    • Whitelisting must be updated everytime the client address changes.
    • Not 100% bulletproof as operators (notably for mobile networks) can NAT multiple connections behind a single publicly addressable IPv4 address.
    • Also IP addresses can be spoofed but I doubt that would be a major concern here.
  • source
  • parent