Scheduled restarts and IP restrictions
Updated 03 Oct 2026Scheduled restarts
Some sources degrade over time or need a restart at a certain hour. In the channel editor, under Schedules, click Scheduled restart:
- Days — Daily, Weekdays, Weekend or the days you choose (at least one);
- Time — the restart time;
- Active — you can pause it without deleting it.
A channel can have any number of schedules. The time follows the Time zone in Settings → Instance, not the server clock — a server in Germany broadcasting for Romania restarts at the time written in the panel. Without schedules, the channel runs continuously and restarts only when the source fails.
IP address restrictions
Controls who can pull the streams (HLS, DASH, HTTP-TS) from the server.
Global list
In Settings → Allowed addresses. Accepted formats:
- single addresses:
203.0.113.10 - networks:
203.0.113.0/24 - ranges:
203.0.113.10-203.0.113.50
IPv4 and IPv6, separated by commas or new lines. A mistyped address blocks saving — so you never end up with a list emptied by mistake.
- Empty list = open access for anyone who reaches the server.
- A filled-in list = only the listed addresses can pull the streams; everyone else gets error 403.
- Changes apply immediately, without a restart.
Careful the first time: add first the address you work from and the addresses of your distribution servers (load balancers, CDN), save, and only then test a stream.
Per-channel list
In the channel editor, under Access → Allowed addresses. If you fill it in, it replaces the global list for that channel. Empty = the global list applies.
Recently rejected
Settings → Recently rejected shows who was refused recently, with the reason and the last attempt. If you blocked one of your own servers by mistake, click Allow and the address goes straight into the list.
Behind a proxy
If the server sits behind a reverse proxy (for example nginx), turn on Behind a proxy (nginx) in Settings → Instance, so Castreon sees the visitor's real address. If the server is exposed directly, leave it off — otherwise the address can be spoofed.
Token for players
As an extra protection, in Settings → Instance you can set a Token for players: streams only open with ?token=… in the address.