Jump to content

Hardcoded port config in EmbyServer service configuration


Recommended Posts

Posted

The service config file (EmbyServer.sc) hardcodes the default ports that synology/Emby is expected to use (http:8096 / https:8920), but these values have no connection to the ports that are actually assigned in the Emby Dashboard/Network UI page.  Consequently, synology/DSM reverse proxy always reports that ports 8096/8920 are unavailable, regardless of the actual Emby configuration.

/var/packages/EmbyServer/target/EmbyServer.sc contents:

[EmbyServer]
title="Emby Server"
desc="Emby Web UI"
port_forward="yes"
src.ports="8096,8920/tcp"
dst.ports="8096,8920/tcp"

 

Posted

Hi, the UI doesn’t let you change it though, right?

Posted

Hey Luke,

The UI presents the fields - 'Public HTTP port number' and 'Public HTTPS port number'.  It allows the user to enter new values (ie. these fields are editable), and the UI won't allow the fields to be blank.  However, after a bit more poking around, it looks like these only control the 'external' port passed to the automatic UPnP mapping (even though I have that feature disabled).  AFAICT, changing those values has no functional purpose otherwise.

What I can confirm from inspecting the host sockets is that with 'Secure connection mode' setting as either 'Disabled' or 'Handled by reverse proxy', the package never activates port 8920 - only HTTP is ever enabled.  I haven't tried loading a certificate (emby intentionally doesn't have access to sensitive paths on my NAS, including certificate locations).

The usecase I have is that I'd like to use the reverse proxy on the NAS (which is more secure than my router) to forward inbound HTTPS traffic on port 8920 to local HTTP on 8096, and to activate HSTS (something my router can't do). The only thing preventing me doing this is the EmbyService.sc file, which seems to be telling the Synology nginx reverse proxy that the emby package is using port 8920, even though it isn't.  Of course I can work around this by hacking the file (presumably until the next upgrades breaks it) or by mapping a different port and have my router NAT present 8920 to the outside world, but would be nice to have a properly working setup :) .
 

FYI - the trigger here is that I'm seeing much more scanning/probing of my router ports than I have in the past, and I'm in the process of locking everything down.

 

 

Posted

You can set the public facing router ports in network settings but the local port numbers are not configurable in our synology package. If they’re not configurable then it shouldn’t be a problem that they’re hardcoded in the manifest.

Posted

It’s hardcoding a value that it’s not using, and therefore preventing the correct reverse proxy setup on the NAS.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...