What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
For Jellyfin access from anywhere, choose either a public HTTPS reverse proxy or a private VPN. A reverse proxy suits a public domain that different devices can reach without joining a private network; a VPN suits access limited to your own devices or a controlled group. Avoid forwarding Jellyfin’s application ports directly to the internet: the Jellyfin project documentation says direct exposure is insecure and not recommended.
Choose a public reverse proxy or a private VPN
Remote access means giving a device outside your home network a route to your Jellyfin server. Jellyfin’s local discovery uses UDP 7359 and works only on the local subnet; it is not a way to find the server over the internet. Jellyfin lists reverse proxies, VPNs, VPS reverse proxies, and public addressing or DNS among possible approaches, but advises against forwarding its ports directly to the internet. Jellyfin networking documentation
| Consideration | Public HTTPS reverse proxy | Private VPN |
|---|---|---|
| Public inbound connection to your home | Usually required: forward TCP 80 and 443 to the proxy, unless using an advanced remote proxy arrangement. | Not required for the documented direct Tailscale setup; it avoids router changes and a public IP. |
| What each client needs | A browser or client that can reach your public domain; no VPN enrollment. | VPN software installed and connected on the server and every client. |
| Domain and certificate | Configure public DNS and a trusted HTTPS certificate. Jellyfin recommends TLS at a separate reverse proxy. | Connect to the server using its Tailscale IP and Jellyfin port; no public domain is needed for direct access. |
| TVs and other unmanaged devices | Often the more convenient fit if the device supports Jellyfin and ordinary internet access. | Can be impractical if the device cannot install or use the VPN app. |
| Network compatibility | Depends on DNS, firewall/router access, and whether your network permits inbound connections. | Useful when behind carrier-grade NAT or when you do not want to open ports. |
| Setup and upkeep | Maintain DNS, firewall rules, proxy, TLS, forwarded headers, and WebSocket support. | Maintain VPN membership and ensure each device joins the tailnet; additional isolation rules may be needed. |
Jellyfin recommends a reverse proxy for a generally accessible public URL and identifies Caddy as its easiest documented option. Choose a VPN when you want access restricted to a known set of devices and can install VPN software on each one. A VPS reverse proxy is an advanced alternative if you cannot expose a home endpoint. Networking · Reverse proxy · Tailscale
Set up a public HTTPS reverse proxy
1. Prepare a public domain and a proxy host
Choose a domain or subdomain and point its DNS A and/or AAAA record to the public IP address that reaches your server. Run a reverse proxy such as Caddy on a host that can reach Jellyfin’s local HTTP listener. The default Jellyfin ports are 8096/TCP for HTTP and 8920/TCP for HTTPS; Jellyfin’s HTTPS listener is disabled by default. The proxy should receive public traffic and forward it internally to Jellyfin rather than exposing the Jellyfin ports directly. Jellyfin networking documentation
#1 Best Overall
- Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
- Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
- Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
- Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
- 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
2. Forward traffic to the proxy, not Jellyfin
At your router and any relevant firewall, allow and forward TCP 80 and 443 to the reverse proxy. Jellyfin’s standard proxy guidance uses those TCP ports; Caddy’s guide notes UDP 443 for HTTP/3, which is optional and is not a Jellyfin application port. Do not forward 8096 or 8920 from the public internet to Jellyfin. Reverse proxy · Caddy
3. Configure HTTPS with a trusted certificate
Use HTTPS at the proxy with a certificate trusted by client devices. Jellyfin strongly discourages self-signed certificates for public access and recommends terminating TLS at a separate reverse proxy. Caddy can obtain and renew HTTPS certificates automatically when public DNS points to the proxy and the required ports are reachable. Networking · Caddy
Rank #2
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
4. Add the proxy to Jellyfin’s Known Proxies
In Jellyfin, open Dashboard > Networking > Known Proxies and enter the actual IP address or addresses of the reverse proxy. With a proxy, Jellyfin otherwise sees the proxy as the connecting client. Once a proxy is trusted, Jellyfin can use its forwarded client and connection headers, including X-Forwarded-For, X-Forwarded-Proto, and X-Forwarded-Host. Jellyfin discards forwarded-for headers from unknown sources to prevent spoofing, so do not trust arbitrary proxy IPs or rely on headers from untrusted clients. Jellyfin reverse proxy documentation
5. Ensure WebSockets pass through
Jellyfin uses WebSockets for various functions. Confirm that your chosen proxy supports and forwards WebSocket connections; a server page may load even when features that depend on the persistent connection do not work correctly. Jellyfin reverse proxy documentation
Rank #3
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
6. Start with a minimal Caddy configuration
For a basic setup where Caddy can reach Jellyfin at 127.0.0.1:8096, the Caddyfile pattern is:
example.com {
reverse_proxy 127.0.0.1:8096
}
Replace example.com with your domain and adjust the upstream address if Jellyfin runs on another host, in a container, or on a different port. Caddy’s equivalent command is caddy reverse-proxy --from example.com --to 127.0.0.1:8096; it assumes DNS points to the machine and that Caddy can bind the required low ports. These are configuration templates, not universal settings. Jellyfin Caddy guide
Rank #4
- Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
- Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
- Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
- Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
- Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
7. Limit who can connect
In Jellyfin’s networking settings, configure local networks as the appropriate comma-separated CIDR ranges, and review the global remote-access setting. Then check each user’s permission for remote connections. Allow only the users who should connect from outside your network. Proxy-based restrictions rely on correct Known Proxies configuration, so verify that before using client IP information in access rules. Networking · Reverse proxy
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Use a VPN when access should stay private
Jellyfin documents Tailscale as an option for networks behind carrier-grade NAT or situations where opening router ports is undesirable. Install Tailscale on the Jellyfin server and on every client, join each device to the same tailnet, then connect to the server’s Tailscale IP address and Jellyfin port, typically 8096. No public IP or router port forwarding is needed for this direct approach, but every device must run the VPN app and have access to the tailnet. Jellyfin Tailscale setup
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
Jellyfin notes that extra, complex configuration may be needed to stop tailnet clients from connecting to one another. If that isolation matters, plan and validate tailnet access controls rather than assuming that joining the VPN grants access only to Jellyfin.
Harden the setup before relying on it
- Do not expose Jellyfin’s ports directly. Keep 8096 and 8920 private; route public requests through the reverse proxy or use a VPN.
- Use trusted HTTPS for public access. Do not substitute a self-signed certificate for a certificate trusted by the devices that will connect.
- Turn off automatic port mapping unless needed. In the setup wizard, disable automatic port mapping unless you specifically require it. Jellyfin says this feature relies on UPnP, which is commonly associated with security concerns. Setup Wizard Walkthrough
- Grant remote access selectively. Match the global remote-access setting, local-network CIDR ranges, and individual user permissions to the people and devices you intend to allow.
- Protect proxy logs. Jellyfin requests can carry authentication details in URL paths or parameters, including
api_key. Restrict access to logs, avoid recording full request paths where possible, or redact sensitive values. Reverse proxy - Do not trust forwarded headers from unknown sources. Add only the real proxy IP addresses to Known Proxies and ensure the proxy supplies the expected forwarded headers.
Decide whether you need a URL subpath
A public domain can serve Jellyfin at its own hostname, such as https://media.example.com. A path such as https://example.com/jellyfin is also supported, but it adds coordination: set the same Base URL in Jellyfin and the proxy, then restart Jellyfin after changing its Base URL. Some client apps do not follow redirects and may need /jellyfin included in the server address. Jellyfin documents possible compatibility breaks for HDHomeRun, DLNA, Sonarr, Radarr, and MrMC, so a dedicated hostname is often the simpler choice. Jellyfin networking documentation
Quick Recap
Troubleshoot remote connections in order
- Check DNS. From outside your home network, confirm the domain resolves to the public endpoint intended to receive the connection. If using a VPN, confirm the client is connected to the correct tailnet and is using the server’s Tailscale IP.
- Check the network path. For a public proxy, verify router forwarding and firewall rules send TCP 80 and 443 to the proxy, not Jellyfin. If your ISP or upstream network does not permit inbound connections, use a VPN or consider an advanced VPS proxy arrangement.
- Check HTTPS. Open the public URL and inspect whether its certificate is valid and trusted by the client. Confirm the proxy can reach Jellyfin’s local listener.
- Check proxy identity and headers. Confirm the proxy’s actual IP is listed in Jellyfin’s Known Proxies and that it forwards the required client and protocol headers.
- Check WebSockets. If the page loads but real-time functions fail, confirm WebSocket forwarding is enabled in the proxy.
- Check the Base URL only if using a subpath. Ensure the path matches in Jellyfin and the proxy, restart Jellyfin after changing it, and include the path in the client address if that app requires it.
- Check access permissions. Confirm Jellyfin’s global remote-access setting and the affected user’s remote-connection permission allow the connection.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

