# Stream engine to serve users only view clip listed on/through my own sites

**URL:** <https://community.wowza.com/t/stream-engine-to-serve-users-only-view-clip-listed-on-through-my-own-sites/92773>\
**Category:** Wowza Streaming Engine\
**Tags:** server-administration\
**Created:** [January 30, 2021, 4:57pm UTC](https://community.wowza.com/t/stream-engine-to-serve-users-only-view-clip-listed-on-through-my-own-sites/92773 "2021-01-30T16:57:45Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![STEMI\_TW](https://avatars.discourse-cdn.com/v4/letter/s/7ab992/32.png) [@STEMI\_TW](https://community.wowza.com/u/STEMI_TW)\
**Post date:** [January 30, 2021, 4:57pm UTC](https://community.wowza.com/t/stream-engine-to-serve-users-only-view-clip-listed-on-through-my-own-sites/92773/1 "2021-01-30T16:57:45Z")

</div>

Greetings.  
my stream engine server can be called to play video directly by VLC like this:  
vlc rtsp://stream.my.domain:1935/vod/_definst_/vod/dir1/video2.mp4  
this make ddos attack possible.

and my websites which have all the clip listed are

[http://site1.my.domain1](http://site1.my.domain1)  
[http://site2.my.domain2](http://site2.my.domain2)

I would like to limit my wowza stream engine server (stream.my.domain) to serve only the above 2 frontend sites (users viewing my videos through/on these 2 sites) so that others can not do the :1935 access activities like the above vlc direct access or other possible ddos attack.

how can I set it up or what are needed to achieve this?

Thanks in advance  
Cheers  
Joshua

---

<div class="post-metadata">

**Author:** ![Rose\_Power-Wowza\_Com](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/rose_power-wowza_com/32/431_2.png) [@Rose\_Power-Wowza\_Com](https://community.wowza.com/u/Rose_Power-Wowza_Com)\
**Post date:** [February 1, 2021, 3:39pm UTC](https://community.wowza.com/t/stream-engine-to-serve-users-only-view-clip-listed-on-through-my-own-sites/92773/2 "2021-02-01T15:39:29Z")

</div>

Hello @STEMI_TW, with how the internet is used now and all the unfortunate tools/ways people can hack a url, there is no 100% solution to stopping it completely. But, you can significantly reduce the chances of it happening and Wowza always recommends rather than just using one security approach, combine several.

You can restrict which domains can access your content by using our RefererValidate module.

From the article:  
_“Adding an image tag or JavaScript to the embedded player webpage with a specified image path that points towards your Wowza server allows Wowza to validate the requestor and then enable the stream for playback. If the player is configured to start automatically or the page may take longer to load, the image tag should be positioned on the page before the embedded player.”_

[https://www.wowza.com/docs/how-to-control-access-to-your-application-by-checking-referer-domain-modulereferervalidate](https://www.wowza.com/docs/how-to-control-access-to-your-application-by-checking-referer-domain-modulereferervalidate)

If that option does not solve the issue for you, we offer a variety of security options to ensure only those you wish to have access to the stream can open it.

These options include:

- Security tokens
- IP blocking
- Geoblocking
- Encryption
- SSL
- Stream Name alias
- Source Authentication  
  

If you’d like to learn more about the security options in Streaming Engine, you can read them here:  
[https://www.wowza.com/docs/security-options-in-wowza-streaming-engine](https://www.wowza.com/docs/security-options-in-wowza-streaming-engine)

---

<div class="post-metadata">

**Author:** ![STEMI\_TW](https://avatars.discourse-cdn.com/v4/letter/s/7ab992/32.png) [@STEMI\_TW](https://community.wowza.com/u/STEMI_TW)\
**Post date:** [February 3, 2021, 2:10am UTC](https://community.wowza.com/t/stream-engine-to-serve-users-only-view-clip-listed-on-through-my-own-sites/92773/3 "2021-02-03T02:10:49Z")

</div>

Hello Rose\_Power-Wowza\_Com]  
Thanks for your reply, I will try to learn all these solutions.

Cheers  
Joshua
