17. OBS Is Refused: access forbidden by rule
17.1 Overview
The default configuration relays Real-Time Messaging Protocol (RTMP) streams from all typical local and docker IPs (172.16.0.0/12,192.168.0.0/16). This restriction can be modified by setting the PUBLISH_IP_RANGE environment variable.
If this mask does not include the IP address of the machine you are streaming from, you will see access forbidden errors in the logs and publishing the stream from OBS to your relay will not be accepted.
17.2 Symptoms
"access forbidden by rule" errors in the relay logs, e.g.:
relay-1 | 2025/11/05 10:34:08 [error] 95#95: *42 access forbidden by rule, client: 172.22.0.1, server: 0.0.0.0:1935
17.3 Solution
-
Find the address the relay refused. It's the
client:value in the log line: -
In
env/relay.env, uncommentPUBLISH_IP_RANGEand add a range that includes that address. Keep the ranges you still need, because this value replaces the default. For a refused address of10.0.0.25: -
Recreate the container so it reads the new value:
-
Start streaming from OBS, then confirm that nothing was refused:
No output means the connection was allowed.
17.4 Choosing an Appropriate PUBLISH_IP_RANGE
17.4.1 Connections From: Other Machines
Use the address the relay logged as client: in Solution step 1, not the address you expect. Choose a range that covers it: /32 for that address only, or its subnet, such as 192.168.1.0/24.
17.4.2 Connections From: The Same Machine
If OBS runs on the same machine as the relay, its connection reaches the relay from the Docker network's gateway address (for example 172.25.0.1), not from 127.0.0.1. The default range 172.16.0.0/12 allows it. If you set your own PUBLISH_IP_RANGE, keep 172.16.0.0/12 in the list.
17.5 Example Ranges
Each value keeps 172.16.0.0/12 so OBS on the relay's own machine can still publish. Drop it only if nothing streams from that machine.
| Description | PUBLISH_IP_RANGE Value |
|---|---|
| Relay machine plus one other machine | 172.16.0.0/12,192.168.1.100/32 |
| Relay machine plus one subnet (192.168.1.x) | 172.16.0.0/12,192.168.1.0/24 |
| Relay machine plus a typical home network | 172.16.0.0/12,192.168.0.0/16 (the default) |
Security Recommendation
Use the most restrictive mask that meets your needs. If you stream from one other machine, use /32 for that machine's address.
17.6 See Also
- Restrict Who Can Publish and Watch - Lock down publishing and playback
- Security - What the relay protects, and what it does not
- Connection Issues - Other connection problems
- Change Relay Settings - Environment variable setup