Coturn server firewall configuration

588 views
Skip to first unread message

Julien Gribonvald

unread,
Nov 4, 2020, 6:46:30 AM11/4/20
to bigbluebu...@googlegroups.com

Hi folks,

We're having some doubts about the undertsanding of the firewall configuration for the coturn server from the documentation here: https://docs.bigbluebutton.org/2.2/setup-turn-server.html#required-ports

Could you confirm that is the good translation of the documentation ?

SRCPorts     DESTPort     Protocol    IO   SRC       DEST     Description
*            3478         TCP/UDP     IN   *         Coturn   coturn listening port
*            443          TCP/UDP     IN   *         Coturn   TLS listening port
49152-65535  16384:32768  UDP         OUT  Coturn    BBB      relay ports range

We understood (from the doc) that the turn server is communicating as a relay with the BBB server on UDP from 49152-65535 port range to BBB port range 16384:32768 (as the BBB server isn't configured on
49152-65535 port range from the documentation). And users come only on 3748 or 443 ports. 

Is it good like that or should we open DEST UDP port to users too ? on which range ?

I've watched on the bbb-install.sh script and the firewall is configured only for the BBB serveur, a UFW configuration is missing for the case installing only coturn.

Thanks.

--
Julien Gribonvald

Julien Gribonvald

unread,
Nov 5, 2020, 6:06:58 AM11/5/20
to bigbluebu...@googlegroups.com

Hi,

I'm sorry I relaunch my post as nobody responded, if someone have a clear idea on how things should works, please your help is requested. I could purpose a PR for the documentation to clarify this part, and also in the bbb-install.sh script.

Best regards.

--
You received this message because you are subscribed to the Google Groups "BigBlueButton-Setup" group.
To unsubscribe from this group and stop receiving emails from it, send an email to bigbluebutton-s...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/bigbluebutton-setup/20375ac1-dcbc-5fb2-943c-ffd204720a27%40recia.fr.
--
Julien Gribonvald

Thierry Kauffmann

unread,
Nov 5, 2020, 9:07:29 AM11/5/20
to BigBlueButton-Setup
Hi Julien,

You are right about your interpretation of the documentation.
Ports 3478 and 443 reflect how you configure the turn server on BigBlueButton instances.
I have made a setup where I only configure port 443 to listen since this port makes most sense : it is open in most cases in Firewalls since it is used for Web traffic.

Kind regards,
Thierry
Message has been deleted

Thierry Kauffmann

unread,
Nov 5, 2020, 9:14:53 AM11/5/20
to BigBlueButton-Setup
might be useful !
Reply all
Reply to author
Forward
0 new messages