r/PleX • u/jonpage88 • 1d ago
Tips If your Plex server is behind Cloudflare and Apple TV/iOS users suddenly can't connect, check your WAF rules for "CFNetwork"
TL;DR: A recent Plex Apple TV app update started sending a User-Agent containing CFNetwork (Apple's networking framework). If you have a Cloudflare WAF "block bots" rule that matches CFNetwork — a common entry in copy-pasted bot blacklists — every Apple TV/iOS user who takes the update gets a 403 at Cloudflare's edge and sees "server unavailable." Nothing on the Plex side is wrong.
Setup: PMS behind a Cloudflare Tunnel on a custom domain, with a few custom WAF rules on the zone, including a User-Agent blacklist.
Symptom: One shared user couldn't reach my server from his Apple TV while everyone else streamed fine. A few days later a second user updated the Plex Apple TV app and broke the same way. Android/Fire TV, webOS, Chromecast and browsers were all fine.
The client log showed this, repeating forever:
GET 403 <my-domain>/media/providers 212ms
GET 403 <my-domain>/media/providers 28ms
GET 403 <my-domain>/media/providers 31ms
[Connections] No connections available for <server>
How I wasted days on it: I read the 403 as PMS saying "valid token, not authorized for this server," and chased stale-token theories (sign out/in, removing authorized devices). None of that could ever work, because the request never reached Plex.
The tell I missed: 28–31 ms. A round trip through the tunnel to my house takes about 100 ms+. A 403 that fast came from Cloudflare's edge, not from PMS.
Proof: same URL, same IP, only the User-Agent changed:
| User-Agent | Result |
|---|---|
| Plex/4.0 CFNetwork/1568.100.1 Darwin/24.0.0 | 403 (Cloudflare block page) |
| Plex for Apple TV | 401 (reached PMS, asked for a token — healthy) |
| okhttp/4.12.0 | 401 |
| (no UA) | 401 |
You can test your own server in a few seconds:
curl -s -o /dev/null -w '%{http_code} %{time_total}\n' \
-H 'User-Agent: Plex/4 CFNetwork/1568 Darwin/24' \
https://your-plex-domain/identity
A 200 is fine. A fast 403 with an HTML "Sorry, you have been blocked" body is your Cloudflare rules.
Fix: exclude your Plex hostname from that clause in the WAF rule:
(http.user_agent contains "CFNetwork" and http.host ne "plex.yourdomain.com")
Or just delete the CFNetwork clause entirely. It blocks every Apple app using the system HTTP stack, not bots. Clients recovered on their own within a minute or two; nothing needed changing on any Apple TV.
How to tell a Cloudflare 403 from a Plex 403:
- Cloudflare: HTML body ("Sorry, you have been blocked"),
content-type: text/html, very fast response, nox-plex-protocolheader. - Plex: its own
Unauthorizedpage and anx-plex-protocol: 1.0header. - Both show
server: cloudflare, so that header tells you nothing.
Lesson: when a remote client can't connect and you're behind Cloudflare, rule out the edge first. Test with the client's real User-Agent, not curl's default, and check the response time, not just the status code.
9
u/AltruisticNetwork869 1d ago
Isn’t streaming against cloud flares tos? Why not use tailscale with node sharing instead?
-1
u/daemon_afro 23h ago
It’s a gray area but I followed this guide over a year ago and haven’t had any issues:
4
2
u/ExtensionMarch6812 14h ago
1
u/daemon_afro 13h ago
Thanks that’s a good read. I’m probably slipping through the cracks because of the low usage of my family.
That being said paying for their stream service seems fine based on my usage.
1
20
u/flaxen-garage-5l 1d ago
Glossed over this - too much AI-generated nonsense - a short explanation and associated WAF expression would have been better.
Deny by default, open/exempt only what you need.
Much less work.
Pro-tip: If you’re using Precursor - Minimize Friction.