Skip to content

17. OBS Is Refused: access forbidden by rule

17.1 Overview

The default configuration relays Real-Time Messaging Protocol (RTMP) streams from all typical local and docker IPs (172.16.0.0/12,192.168.0.0/16). This restriction can be modified by setting the PUBLISH_IP_RANGE environment variable.

If this mask does not include the IP address of the machine you are streaming from, you will see access forbidden errors in the logs and publishing the stream from OBS to your relay will not be accepted.

17.2 Symptoms

"access forbidden by rule" errors in the relay logs, e.g.:

relay-1  | 2025/11/05 10:34:08 [error] 95#95: *42 access forbidden by rule, client: 172.22.0.1, server: 0.0.0.0:1935

17.3 Solution

  1. Find the address the relay refused. It's the client: value in the log line:

    docker compose logs relay | grep "access forbidden"
    
  2. In env/relay.env, uncomment PUBLISH_IP_RANGE and add a range that includes that address. Keep the ranges you still need, because this value replaces the default. For a refused address of 10.0.0.25:

    PUBLISH_IP_RANGE=10.0.0.0/24,172.16.0.0/12,192.168.0.0/16
    
  3. Recreate the container so it reads the new value:

    docker compose up -d --force-recreate
    
  4. Start streaming from OBS, then confirm that nothing was refused:

    docker compose logs relay | grep "access forbidden"
    

    No output means the connection was allowed.

17.4 Choosing an Appropriate PUBLISH_IP_RANGE

17.4.1 Connections From: Other Machines

Use the address the relay logged as client: in Solution step 1, not the address you expect. Choose a range that covers it: /32 for that address only, or its subnet, such as 192.168.1.0/24.

17.4.2 Connections From: The Same Machine

If OBS runs on the same machine as the relay, its connection reaches the relay from the Docker network's gateway address (for example 172.25.0.1), not from 127.0.0.1. The default range 172.16.0.0/12 allows it. If you set your own PUBLISH_IP_RANGE, keep 172.16.0.0/12 in the list.

17.5 Example Ranges

Each value keeps 172.16.0.0/12 so OBS on the relay's own machine can still publish. Drop it only if nothing streams from that machine.

Description PUBLISH_IP_RANGE Value
Relay machine plus one other machine 172.16.0.0/12,192.168.1.100/32
Relay machine plus one subnet (192.168.1.x) 172.16.0.0/12,192.168.1.0/24
Relay machine plus a typical home network 172.16.0.0/12,192.168.0.0/16 (the default)

Security Recommendation

Use the most restrictive mask that meets your needs. If you stream from one other machine, use /32 for that machine's address.

17.6 See Also