Plex vs AP7

Comments

8 comments

  • Avatar
    Firewalla

    Do you mean, you don't want your TV to talk to anything on the LAN besides your Plex server? This is possible with VqLAN once we made the allow feature. 

    Today you can put TV and Plex server in the same group and turn VqLAN on, that will microsegment both together. And in a month or so, you can isolate the TV and only allow your Plex server to talk to it. 

    2
    Comment actions Permalink
  • Avatar
    MGJ

    Correct, I would not even want the TV to be able to talk to the server other than the Plex server app on the server (NAS).

    From what I've seen so far, it talks to port 32400 which is the standard Plex port, a little to 5000 which is the standard Synology OS port which may or may not be required, and 50001 which is a DNLA port but that's probably not needed by the app, that's just the TV which found PLEX as a DNLA server I think.

    So in theory, using ports segregation if that feature is available, I could only allow the TV to talk to just 32400, maybe 5000 if required.

    TV's are notorious for being unsafe and/or snooping where they should not be so I want to barricade it as much as possible. However since the Plex server is the main files server as well, with a bunch of other applications running on it, it can't be isolated from the other devices, PC's, phones, tablets, surveillance cams, so microsegmenting the TV and the NAS together would probably not work, unless in the future there was a way to partially join together several microsegments, like so. The NAS is wired to the router so it would not be talking to the AP7 directly, the TV and other devices would.


    0
    Comment actions Permalink
  • Avatar
    Firewalla

    When you receive the AP7 unit, the VqLAN feature can isolate devices or device groups. And may be a week or two later, you should get "allow" device feature. 

    So with above, you can do PC/Phone/ in one group (turn VqLAN on)

    NAS: turn on isolation

    TV: turn on isolation

    Then on the TV side you can allow NAS. 

    There is no port configuration for LAN side yet, but it is possible to add it; we are just keeping things simple for now

    0
    Comment actions Permalink
  • Avatar
    bassplayer_4life

    Is there a way to allow only traffic through port 32400? Maybe my question should be, is there any benefit to only allowing traffic on port 32400 and if so, how is this done?

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    There is no port information for "allowing" one device to talk to another. So you will need to allow the A talk to B, on all ports. 

    0
    Comment actions Permalink
  • Avatar
    bassplayer_4life

    Would using rules in conjunction with microsegmentation allow for exclusion of access except for port 32400?

    0
    Comment actions Permalink
  • Avatar
    bassplayer_4life

    Also, the first question I think I should be asking is it any safer to try to limit access to one port vs giving the access to the device as a whole?

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    VqLAN is layer 2 + 3 filtering, I don't think it will work to add a rule to include TCP/UDP ports. 

    0
    Comment actions Permalink

Please sign in to leave a comment.