When Plex can't open the door automatically, you add one rule to your router yourself: when the internet knocks on port 32400, send the knock to the Plex machine. Ten minutes, and you only do it once.
1
Pin the port in PlexSettings, then Remote Access. Tick “Manually specify public port” and leave it at 32400. Click Apply.
2
Open your router's admin pageIn a browser at home, try http://192.168.1.1 or http://192.168.0.1. The password is often printed on a sticker on the router itself.
3
Find the port forwarding sectionRouters hide it under names like Advanced, NAT Forwarding, or Virtual Servers. If you get lost, search the web for “port forwarding” plus your router's model number.
4
Add the ruleExternal port 32400. Internal port 32400. Protocol TCP. Device: your Plex machine, at its permanent address.
5
Save, then retry in PlexBack on the Remote Access page, click Apply or Retry and wait for the green check.
6
Verify it stays fixedSign in with Plex on Eyeball and it watches the server from the internet. If the rule ever stops working, you get an email instead of a complaint.
TCP alone is enough; Plex does not need UDP forwarded. The external port can be any free number if 32400 is taken. Put the same number in Plex's “Manually specify public port” box.