coturn.html 30 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366
  1. <!DOCTYPE HTML>
  2. <html lang="en" class="sidebar-visible no-js light">
  3. <head>
  4. <!-- Book generated using mdBook -->
  5. <meta charset="UTF-8">
  6. <title>coturn TURN server - Synapse</title>
  7. <!-- Custom HTML head -->
  8. <meta content="text/html; charset=utf-8" http-equiv="Content-Type">
  9. <meta name="description" content="">
  10. <meta name="viewport" content="width=device-width, initial-scale=1">
  11. <meta name="theme-color" content="#ffffff" />
  12. <link rel="icon" href="../../favicon.svg">
  13. <link rel="shortcut icon" href="../../favicon.png">
  14. <link rel="stylesheet" href="../../css/variables.css">
  15. <link rel="stylesheet" href="../../css/general.css">
  16. <link rel="stylesheet" href="../../css/chrome.css">
  17. <link rel="stylesheet" href="../../css/print.css" media="print">
  18. <!-- Fonts -->
  19. <link rel="stylesheet" href="../../FontAwesome/css/font-awesome.css">
  20. <link rel="stylesheet" href="../../fonts/fonts.css">
  21. <!-- Highlight.js Stylesheets -->
  22. <link rel="stylesheet" href="../../highlight.css">
  23. <link rel="stylesheet" href="../../tomorrow-night.css">
  24. <link rel="stylesheet" href="../../ayu-highlight.css">
  25. <!-- Custom theme stylesheets -->
  26. <link rel="stylesheet" href="../../docs/website_files/table-of-contents.css">
  27. <link rel="stylesheet" href="../../docs/website_files/remove-nav-buttons.css">
  28. <link rel="stylesheet" href="../../docs/website_files/indent-section-headers.css">
  29. <link rel="stylesheet" href="../../docs/website_files/version-picker.css">
  30. </head>
  31. <body>
  32. <!-- Provide site root to javascript -->
  33. <script type="text/javascript">
  34. var path_to_root = "../../";
  35. var default_theme = window.matchMedia("(prefers-color-scheme: dark)").matches ? "navy" : "light";
  36. </script>
  37. <!-- Work around some values being stored in localStorage wrapped in quotes -->
  38. <script type="text/javascript">
  39. try {
  40. var theme = localStorage.getItem('mdbook-theme');
  41. var sidebar = localStorage.getItem('mdbook-sidebar');
  42. if (theme.startsWith('"') && theme.endsWith('"')) {
  43. localStorage.setItem('mdbook-theme', theme.slice(1, theme.length - 1));
  44. }
  45. if (sidebar.startsWith('"') && sidebar.endsWith('"')) {
  46. localStorage.setItem('mdbook-sidebar', sidebar.slice(1, sidebar.length - 1));
  47. }
  48. } catch (e) { }
  49. </script>
  50. <!-- Set the theme before any content is loaded, prevents flash -->
  51. <script type="text/javascript">
  52. var theme;
  53. try { theme = localStorage.getItem('mdbook-theme'); } catch(e) { }
  54. if (theme === null || theme === undefined) { theme = default_theme; }
  55. var html = document.querySelector('html');
  56. html.classList.remove('no-js')
  57. html.classList.remove('light')
  58. html.classList.add(theme);
  59. html.classList.add('js');
  60. </script>
  61. <!-- Hide / unhide sidebar before it is displayed -->
  62. <script type="text/javascript">
  63. var html = document.querySelector('html');
  64. var sidebar = 'hidden';
  65. if (document.body.clientWidth >= 1080) {
  66. try { sidebar = localStorage.getItem('mdbook-sidebar'); } catch(e) { }
  67. sidebar = sidebar || 'visible';
  68. }
  69. html.classList.remove('sidebar-visible');
  70. html.classList.add("sidebar-" + sidebar);
  71. </script>
  72. <nav id="sidebar" class="sidebar" aria-label="Table of contents">
  73. <div class="sidebar-scrollbox">
  74. <ol class="chapter"><li class="chapter-item expanded affix "><li class="part-title">Introduction</li><li class="chapter-item expanded "><a href="../../welcome_and_overview.html">Welcome and Overview</a></li><li class="chapter-item expanded affix "><li class="part-title">Setup</li><li class="chapter-item expanded "><a href="../../setup/installation.html">Installation</a></li><li class="chapter-item expanded "><a href="../../postgres.html">Using Postgres</a></li><li class="chapter-item expanded "><a href="../../reverse_proxy.html">Configuring a Reverse Proxy</a></li><li class="chapter-item expanded "><a href="../../setup/forward_proxy.html">Configuring a Forward/Outbound Proxy</a></li><li class="chapter-item expanded "><a href="../../turn-howto.html">Configuring a Turn Server</a></li><li><ol class="section"><li class="chapter-item expanded "><a href="../../setup/turn/coturn.html" class="active">coturn TURN server</a></li><li class="chapter-item expanded "><a href="../../setup/turn/eturnal.html">eturnal TURN server</a></li></ol></li><li class="chapter-item expanded "><a href="../../delegate.html">Delegation</a></li><li class="chapter-item expanded affix "><li class="part-title">Upgrading</li><li class="chapter-item expanded "><a href="../../upgrade.html">Upgrading between Synapse Versions</a></li><li class="chapter-item expanded affix "><li class="part-title">Usage</li><li class="chapter-item expanded "><a href="../../federate.html">Federation</a></li><li class="chapter-item expanded "><a href="../../usage/configuration/index.html">Configuration</a></li><li><ol class="section"><li class="chapter-item expanded "><a href="../../usage/configuration/config_documentation.html">Configuration Manual</a></li><li class="chapter-item expanded "><a href="../../usage/configuration/homeserver_sample_config.html">Homeserver Sample Config File</a></li><li class="chapter-item expanded "><a href="../../usage/configuration/logging_sample_config.html">Logging Sample Config File</a></li><li class="chapter-item expanded "><a href="../../structured_logging.html">Structured Logging</a></li><li class="chapter-item expanded "><a href="../../templates.html">Templates</a></li><li class="chapter-item expanded "><a href="../../usage/configuration/user_authentication/index.html">User Authentication</a></li><li><ol class="section"><li class="chapter-item expanded "><a href="../../usage/configuration/user_authentication/single_sign_on/index.html">Single-Sign On</a></li><li><ol class="section"><li class="chapter-item expanded "><a href="../../openid.html">OpenID Connect</a></li><li class="chapter-item expanded "><a href="../../usage/configuration/user_authentication/single_sign_on/saml.html">SAML</a></li><li class="chapter-item expanded "><a href="../../usage/configuration/user_authentication/single_sign_on/cas.html">CAS</a></li><li class="chapter-item expanded "><a href="../../sso_mapping_providers.html">SSO Mapping Providers</a></li></ol></li><li class="chapter-item expanded "><a href="../../password_auth_providers.html">Password Auth Providers</a></li><li class="chapter-item expanded "><a href="../../jwt.html">JSON Web Tokens</a></li><li class="chapter-item expanded "><a href="../../usage/configuration/user_authentication/refresh_tokens.html">Refresh Tokens</a></li></ol></li><li class="chapter-item expanded "><a href="../../CAPTCHA_SETUP.html">Registration Captcha</a></li><li class="chapter-item expanded "><a href="../../application_services.html">Application Services</a></li><li class="chapter-item expanded "><a href="../../server_notices.html">Server Notices</a></li><li class="chapter-item expanded "><a href="../../consent_tracking.html">Consent Tracking</a></li><li class="chapter-item expanded "><a href="../../user_directory.html">User Directory</a></li><li class="chapter-item expanded "><a href="../../message_retention_policies.html">Message Retention Policies</a></li><li class="chapter-item expanded "><a href="../../modules/index.html">Pluggable Modules</a></li><li><ol class="section"><li class="chapter-item expanded "><a href="../../modules/writing_a_module.html">Writing a module</a></li><li><ol class="section"><li class="chapter-item expanded "><a href="../../modules/spam_checker_callbacks.html">Spam checker callbacks</a></li><li class="chapter-item expanded "><a href="../../modules/third_party_rules_callbacks.html">Third-party rules callbacks</a></li><li class="chapter-item expanded "><a href="../../modules/presence_router_callbacks.html">Presence router callbacks</a></li><li class="chapter-item expanded "><a href="../../modules/account_validity_callbacks.html">Account validity callbacks</a></li><li class="chapter-item expanded "><a href="../../modules/password_auth_provider_callbacks.html">Password auth provider callbacks</a></li><li class="chapter-item expanded "><a href="../../modules/background_update_controller_callbacks.html">Background update controller callbacks</a></li><li class="chapter-item expanded "><a href="../../modules/account_data_callbacks.html">Account data callbacks</a></li><li class="chapter-item expanded "><a href="../../modules/add_extra_fields_to_client_events_unsigned.html">Add extra fields to client events unsigned section callbacks</a></li><li class="chapter-item expanded "><a href="../../modules/porting_legacy_module.html">Porting a legacy module to the new interface</a></li></ol></li></ol></li><li class="chapter-item expanded "><a href="../../workers.html">Workers</a></li><li><ol class="section"><li class="chapter-item expanded "><a href="../../synctl_workers.html">Using synctl with Workers</a></li><li class="chapter-item expanded "><a href="../../systemd-with-workers/index.html">Systemd</a></li></ol></li></ol></li><li class="chapter-item expanded "><a href="../../usage/administration/index.html">Administration</a></li><li><ol class="section"><li class="chapter-item expanded "><a href="../../usage/administration/admin_api/index.html">Admin API</a></li><li><ol class="section"><li class="chapter-item expanded "><a href="../../admin_api/account_validity.html">Account Validity</a></li><li class="chapter-item expanded "><a href="../../usage/administration/admin_api/background_updates.html">Background Updates</a></li><li class="chapter-item expanded "><a href="../../admin_api/event_reports.html">Event Reports</a></li><li class="chapter-item expanded "><a href="../../admin_api/experimental_features.html">Experimental Features</a></li><li class="chapter-item expanded "><a href="../../admin_api/media_admin_api.html">Media</a></li><li class="chapter-item expanded "><a href="../../admin_api/purge_history_api.html">Purge History</a></li><li class="chapter-item expanded "><a href="../../admin_api/register_api.html">Register Users</a></li><li class="chapter-item expanded "><a href="../../usage/administration/admin_api/registration_tokens.html">Registration Tokens</a></li><li class="chapter-item expanded "><a href="../../admin_api/room_membership.html">Manipulate Room Membership</a></li><li class="chapter-item expanded "><a href="../../admin_api/rooms.html">Rooms</a></li><li class="chapter-item expanded "><a href="../../admin_api/server_notices.html">Server Notices</a></li><li class="chapter-item expanded "><a href="../../admin_api/statistics.html">Statistics</a></li><li class="chapter-item expanded "><a href="../../admin_api/user_admin_api.html">Users</a></li><li class="chapter-item expanded "><a href="../../admin_api/version_api.html">Server Version</a></li><li class="chapter-item expanded "><a href="../../usage/administration/admin_api/federation.html">Federation</a></li></ol></li><li class="chapter-item expanded "><a href="../../manhole.html">Manhole</a></li><li class="chapter-item expanded "><a href="../../metrics-howto.html">Monitoring</a></li><li><ol class="section"><li class="chapter-item expanded "><a href="../../usage/administration/monitoring/reporting_homeserver_usage_statistics.html">Reporting Homeserver Usage Statistics</a></li></ol></li><li class="chapter-item expanded "><a href="../../usage/administration/monthly_active_users.html">Monthly Active Users</a></li><li class="chapter-item expanded "><a href="../../usage/administration/understanding_synapse_through_grafana_graphs.html">Understanding Synapse Through Grafana Graphs</a></li><li class="chapter-item expanded "><a href="../../usage/administration/useful_sql_for_admins.html">Useful SQL for Admins</a></li><li class="chapter-item expanded "><a href="../../usage/administration/database_maintenance_tools.html">Database Maintenance Tools</a></li><li class="chapter-item expanded "><a href="../../usage/administration/state_groups.html">State Groups</a></li><li class="chapter-item expanded "><a href="../../usage/administration/request_log.html">Request log format</a></li><li class="chapter-item expanded "><a href="../../usage/administration/admin_faq.html">Admin FAQ</a></li><li class="chapter-item expanded "><div>Scripts</div></li></ol></li><li class="chapter-item expanded "><li class="part-title">Development</li><li class="chapter-item expanded "><a href="../../development/contributing_guide.html">Contributing Guide</a></li><li class="chapter-item expanded "><a href="../../code_style.html">Code Style</a></li><li class="chapter-item expanded "><a href="../../development/reviews.html">Reviewing Code</a></li><li class="chapter-item expanded "><a href="../../development/releases.html">Release Cycle</a></li><li class="chapter-item expanded "><a href="../../development/git.html">Git Usage</a></li><li class="chapter-item expanded "><div>Testing</div></li><li><ol class="section"><li class="chapter-item expanded "><a href="../../development/demo.html">Demo scripts</a></li></ol></li><li class="chapter-item expanded "><a href="../../opentracing.html">OpenTracing</a></li><li class="chapter-item expanded "><a href="../../development/database_schema.html">Database Schemas</a></li><li class="chapter-item expanded "><a href="../../development/experimental_features.html">Experimental features</a></li><li class="chapter-item expanded "><a href="../../development/dependencies.html">Dependency management</a></li><li class="chapter-item expanded "><div>Synapse Architecture</div></li><li><ol class="section"><li class="chapter-item expanded "><a href="../../development/synapse_architecture/cancellation.html">Cancellation</a></li><li class="chapter-item expanded "><a href="../../log_contexts.html">Log Contexts</a></li><li class="chapter-item expanded "><a href="../../replication.html">Replication</a></li><li class="chapter-item expanded "><a href="../../development/synapse_architecture/streams.html">Streams</a></li><li class="chapter-item expanded "><a href="../../tcp_replication.html">TCP Replication</a></li><li class="chapter-item expanded "><a href="../../development/synapse_architecture/faster_joins.html">Faster remote joins</a></li></ol></li><li class="chapter-item expanded "><a href="../../development/internal_documentation/index.html">Internal Documentation</a></li><li><ol class="section"><li class="chapter-item expanded "><div>Single Sign-On</div></li><li><ol class="section"><li class="chapter-item expanded "><a href="../../development/saml.html">SAML</a></li><li class="chapter-item expanded "><a href="../../development/cas.html">CAS</a></li></ol></li><li class="chapter-item expanded "><a href="../../development/room-dag-concepts.html">Room DAG concepts</a></li><li class="chapter-item expanded "><div>State Resolution</div></li><li><ol class="section"><li class="chapter-item expanded "><a href="../../auth_chain_difference_algorithm.html">The Auth Chain Difference Algorithm</a></li></ol></li><li class="chapter-item expanded "><a href="../../media_repository.html">Media Repository</a></li><li class="chapter-item expanded "><a href="../../room_and_user_statistics.html">Room and User Statistics</a></li></ol></li><li class="chapter-item expanded "><div>Scripts</div></li><li class="chapter-item expanded affix "><li class="part-title">Other</li><li class="chapter-item expanded "><a href="../../deprecation_policy.html">Dependency Deprecation Policy</a></li><li class="chapter-item expanded "><a href="../../other/running_synapse_on_single_board_computers.html">Running Synapse on a Single-Board Computer</a></li></ol>
  75. </div>
  76. <div id="sidebar-resize-handle" class="sidebar-resize-handle"></div>
  77. </nav>
  78. <div id="page-wrapper" class="page-wrapper">
  79. <div class="page">
  80. <div id="menu-bar-hover-placeholder"></div>
  81. <div id="menu-bar" class="menu-bar sticky bordered">
  82. <div class="left-buttons">
  83. <button id="sidebar-toggle" class="icon-button" type="button" title="Toggle Table of Contents" aria-label="Toggle Table of Contents" aria-controls="sidebar">
  84. <i class="fa fa-bars"></i>
  85. </button>
  86. <button id="theme-toggle" class="icon-button" type="button" title="Change theme" aria-label="Change theme" aria-haspopup="true" aria-expanded="false" aria-controls="theme-list">
  87. <i class="fa fa-paint-brush"></i>
  88. </button>
  89. <ul id="theme-list" class="theme-popup" aria-label="Themes" role="menu">
  90. <li role="none"><button role="menuitem" class="theme" id="light">Light (default)</button></li>
  91. <li role="none"><button role="menuitem" class="theme" id="rust">Rust</button></li>
  92. <li role="none"><button role="menuitem" class="theme" id="coal">Coal</button></li>
  93. <li role="none"><button role="menuitem" class="theme" id="navy">Navy</button></li>
  94. <li role="none"><button role="menuitem" class="theme" id="ayu">Ayu</button></li>
  95. </ul>
  96. <button id="search-toggle" class="icon-button" type="button" title="Search. (Shortkey: s)" aria-label="Toggle Searchbar" aria-expanded="false" aria-keyshortcuts="S" aria-controls="searchbar">
  97. <i class="fa fa-search"></i>
  98. </button>
  99. <div class="version-picker">
  100. <div class="dropdown">
  101. <div class="select">
  102. <span></span>
  103. <i class="fa fa-chevron-down"></i>
  104. </div>
  105. <input type="hidden" name="version">
  106. <ul class="dropdown-menu">
  107. <!-- Versions will be added dynamically in version-picker.js -->
  108. </ul>
  109. </div>
  110. </div>
  111. </div>
  112. <h1 class="menu-title">Synapse</h1>
  113. <div class="right-buttons">
  114. <a href="../../print.html" title="Print this book" aria-label="Print this book">
  115. <i id="print-button" class="fa fa-print"></i>
  116. </a>
  117. <a href="https://github.com/matrix-org/synapse" title="Git repository" aria-label="Git repository">
  118. <i id="git-repository-button" class="fa fa-github"></i>
  119. </a>
  120. <a href="https://github.com/matrix-org/synapse/edit/develop/docs/setup/turn/coturn.md" title="Suggest an edit" aria-label="Suggest an edit">
  121. <i id="git-edit-button" class="fa fa-edit"></i>
  122. </a>
  123. </div>
  124. </div>
  125. <div id="search-wrapper" class="hidden">
  126. <form id="searchbar-outer" class="searchbar-outer">
  127. <input type="search" id="searchbar" name="searchbar" placeholder="Search this book ..." aria-controls="searchresults-outer" aria-describedby="searchresults-header">
  128. </form>
  129. <div id="searchresults-outer" class="searchresults-outer hidden">
  130. <div id="searchresults-header" class="searchresults-header"></div>
  131. <ul id="searchresults">
  132. </ul>
  133. </div>
  134. </div>
  135. <!-- Apply ARIA attributes after the sidebar and the sidebar toggle button are added to the DOM -->
  136. <script type="text/javascript">
  137. document.getElementById('sidebar-toggle').setAttribute('aria-expanded', sidebar === 'visible');
  138. document.getElementById('sidebar').setAttribute('aria-hidden', sidebar !== 'visible');
  139. Array.from(document.querySelectorAll('#sidebar a')).forEach(function(link) {
  140. link.setAttribute('tabIndex', sidebar === 'visible' ? 0 : -1);
  141. });
  142. </script>
  143. <div id="content" class="content">
  144. <main>
  145. <!-- Page table of contents -->
  146. <div class="sidetoc">
  147. <nav class="pagetoc"></nav>
  148. </div>
  149. <h1 id="coturn-turn-server"><a class="header" href="#coturn-turn-server">coturn TURN server</a></h1>
  150. <p>The following sections describe how to install <a href="https://github.com/coturn/coturn">coturn</a> (which implements the TURN REST API).</p>
  151. <h2 id="coturn-setup"><a class="header" href="#coturn-setup"><code>coturn</code> setup</a></h2>
  152. <h3 id="initial-installation"><a class="header" href="#initial-installation">Initial installation</a></h3>
  153. <p>The TURN daemon <code>coturn</code> is available from a variety of sources such as native package managers, or installation from source.</p>
  154. <h4 id="debian-and-ubuntu-based-distributions"><a class="header" href="#debian-and-ubuntu-based-distributions">Debian and Ubuntu based distributions</a></h4>
  155. <p>Just install the debian package:</p>
  156. <pre><code class="language-sh">sudo apt install coturn
  157. </code></pre>
  158. <p>This will install and start a systemd service called <code>coturn</code>.</p>
  159. <h4 id="source-installation"><a class="header" href="#source-installation">Source installation</a></h4>
  160. <ol>
  161. <li>
  162. <p>Download the <a href="https://github.com/coturn/coturn/releases/latest">latest release</a> from github. Unpack it and <code>cd</code> into the directory.</p>
  163. </li>
  164. <li>
  165. <p>Configure it:</p>
  166. <pre><code class="language-sh">./configure
  167. </code></pre>
  168. <p>You may need to install <code>libevent2</code>: if so, you should do so in
  169. the way recommended by your operating system. You can ignore
  170. warnings about lack of database support: a database is unnecessary
  171. for this purpose.</p>
  172. </li>
  173. <li>
  174. <p>Build and install it:</p>
  175. <pre><code class="language-sh">make
  176. sudo make install
  177. </code></pre>
  178. </li>
  179. </ol>
  180. <h3 id="configuration"><a class="header" href="#configuration">Configuration</a></h3>
  181. <ol>
  182. <li>
  183. <p>Create or edit the config file in <code>/etc/turnserver.conf</code>. The relevant
  184. lines, with example values, are:</p>
  185. <pre><code>use-auth-secret
  186. static-auth-secret=[your secret key here]
  187. realm=turn.myserver.org
  188. </code></pre>
  189. <p>See <code>turnserver.conf</code> for explanations of the options. One way to generate
  190. the <code>static-auth-secret</code> is with <code>pwgen</code>:</p>
  191. <pre><code class="language-sh">pwgen -s 64 1
  192. </code></pre>
  193. <p>A <code>realm</code> must be specified, but its value is somewhat arbitrary. (It is
  194. sent to clients as part of the authentication flow.) It is conventional to
  195. set it to be your server name.</p>
  196. </li>
  197. <li>
  198. <p>You will most likely want to configure <code>coturn</code> to write logs somewhere. The
  199. easiest way is normally to send them to the syslog:</p>
  200. <pre><code class="language-sh">syslog
  201. </code></pre>
  202. <p>(in which case, the logs will be available via <code>journalctl -u coturn</code> on a
  203. systemd system). Alternatively, <code>coturn</code> can be configured to write to a
  204. logfile - check the example config file supplied with <code>coturn</code>.</p>
  205. </li>
  206. <li>
  207. <p>Consider your security settings. TURN lets users request a relay which will
  208. connect to arbitrary IP addresses and ports. The following configuration is
  209. suggested as a minimum starting point:</p>
  210. <pre><code># VoIP traffic is all UDP. There is no reason to let users connect to arbitrary TCP endpoints via the relay.
  211. no-tcp-relay
  212. # don't let the relay ever try to connect to private IP address ranges within your network (if any)
  213. # given the turn server is likely behind your firewall, remember to include any privileged public IPs too.
  214. denied-peer-ip=10.0.0.0-10.255.255.255
  215. denied-peer-ip=192.168.0.0-192.168.255.255
  216. denied-peer-ip=172.16.0.0-172.31.255.255
  217. # recommended additional local peers to block, to mitigate external access to internal services.
  218. # https://www.rtcsec.com/article/slack-webrtc-turn-compromise-and-bug-bounty/#how-to-fix-an-open-turn-relay-to-address-this-vulnerability
  219. no-multicast-peers
  220. denied-peer-ip=0.0.0.0-0.255.255.255
  221. denied-peer-ip=100.64.0.0-100.127.255.255
  222. denied-peer-ip=127.0.0.0-127.255.255.255
  223. denied-peer-ip=169.254.0.0-169.254.255.255
  224. denied-peer-ip=192.0.0.0-192.0.0.255
  225. denied-peer-ip=192.0.2.0-192.0.2.255
  226. denied-peer-ip=192.88.99.0-192.88.99.255
  227. denied-peer-ip=198.18.0.0-198.19.255.255
  228. denied-peer-ip=198.51.100.0-198.51.100.255
  229. denied-peer-ip=203.0.113.0-203.0.113.255
  230. denied-peer-ip=240.0.0.0-255.255.255.255
  231. # special case the turn server itself so that client-&gt;TURN-&gt;TURN-&gt;client flows work
  232. # this should be one of the turn server's listening IPs
  233. allowed-peer-ip=10.0.0.1
  234. # consider whether you want to limit the quota of relayed streams per user (or total) to avoid risk of DoS.
  235. user-quota=12 # 4 streams per video call, so 12 streams = 3 simultaneous relayed calls per user.
  236. total-quota=1200
  237. </code></pre>
  238. </li>
  239. <li>
  240. <p>Also consider supporting TLS/DTLS. To do this, add the following settings
  241. to <code>turnserver.conf</code>:</p>
  242. <pre><code># TLS certificates, including intermediate certs.
  243. # For Let's Encrypt certificates, use `fullchain.pem` here.
  244. cert=/path/to/fullchain.pem
  245. # TLS private key file
  246. pkey=/path/to/privkey.pem
  247. # Ensure the configuration lines that disable TLS/DTLS are commented-out or removed
  248. #no-tls
  249. #no-dtls
  250. </code></pre>
  251. <p>In this case, replace the <code>turn:</code> schemes in the <code>turn_uris</code> settings below
  252. with <code>turns:</code>.</p>
  253. <p>We recommend that you only try to set up TLS/DTLS once you have set up a
  254. basic installation and got it working.</p>
  255. <p>NB: If your TLS certificate was provided by Let's Encrypt, TLS/DTLS will
  256. not work with any Matrix client that uses Chromium's WebRTC library. This
  257. currently includes Element Android &amp; iOS; for more details, see their
  258. <a href="https://github.com/vector-im/element-android/issues/1533">respective</a>
  259. <a href="https://github.com/vector-im/element-ios/issues/2712">issues</a> as well as the underlying
  260. <a href="https://bugs.chromium.org/p/webrtc/issues/detail?id=11710">WebRTC issue</a>.
  261. Consider using a ZeroSSL certificate for your TURN server as a working alternative.</p>
  262. </li>
  263. <li>
  264. <p>Ensure your firewall allows traffic into the TURN server on the ports
  265. you've configured it to listen on (By default: 3478 and 5349 for TURN
  266. traffic (remember to allow both TCP and UDP traffic), and ports 49152-65535
  267. for the UDP relay.)</p>
  268. </li>
  269. <li>
  270. <p>If your TURN server is behind NAT, the NAT gateway must have an external,
  271. publicly-reachable IP address. You must configure <code>coturn</code> to advertise that
  272. address to connecting clients:</p>
  273. <pre><code>external-ip=EXTERNAL_NAT_IPv4_ADDRESS
  274. </code></pre>
  275. <p>You may optionally limit the TURN server to listen only on the local
  276. address that is mapped by NAT to the external address:</p>
  277. <pre><code>listening-ip=INTERNAL_TURNSERVER_IPv4_ADDRESS
  278. </code></pre>
  279. <p>If your NAT gateway is reachable over both IPv4 and IPv6, you may
  280. configure <code>coturn</code> to advertise each available address:</p>
  281. <pre><code>external-ip=EXTERNAL_NAT_IPv4_ADDRESS
  282. external-ip=EXTERNAL_NAT_IPv6_ADDRESS
  283. </code></pre>
  284. <p>When advertising an external IPv6 address, ensure that the firewall and
  285. network settings of the system running your TURN server are configured to
  286. accept IPv6 traffic, and that the TURN server is listening on the local
  287. IPv6 address that is mapped by NAT to the external IPv6 address.</p>
  288. </li>
  289. <li>
  290. <p>(Re)start the turn server:</p>
  291. <ul>
  292. <li>
  293. <p>If you used the Debian package (or have set up a systemd unit yourself):</p>
  294. <pre><code class="language-sh">sudo systemctl restart coturn
  295. </code></pre>
  296. </li>
  297. <li>
  298. <p>If you built from source:</p>
  299. <pre><code class="language-sh">/usr/local/bin/turnserver -o
  300. </code></pre>
  301. </li>
  302. </ul>
  303. </li>
  304. </ol>
  305. </main>
  306. <nav class="nav-wrapper" aria-label="Page navigation">
  307. <!-- Mobile navigation buttons -->
  308. <a rel="prev" href="../../turn-howto.html" class="mobile-nav-chapters previous" title="Previous chapter" aria-label="Previous chapter" aria-keyshortcuts="Left">
  309. <i class="fa fa-angle-left"></i>
  310. </a>
  311. <a rel="next" href="../../setup/turn/eturnal.html" class="mobile-nav-chapters next" title="Next chapter" aria-label="Next chapter" aria-keyshortcuts="Right">
  312. <i class="fa fa-angle-right"></i>
  313. </a>
  314. <div style="clear: both"></div>
  315. </nav>
  316. </div>
  317. </div>
  318. <nav class="nav-wide-wrapper" aria-label="Page navigation">
  319. <a rel="prev" href="../../turn-howto.html" class="nav-chapters previous" title="Previous chapter" aria-label="Previous chapter" aria-keyshortcuts="Left">
  320. <i class="fa fa-angle-left"></i>
  321. </a>
  322. <a rel="next" href="../../setup/turn/eturnal.html" class="nav-chapters next" title="Next chapter" aria-label="Next chapter" aria-keyshortcuts="Right">
  323. <i class="fa fa-angle-right"></i>
  324. </a>
  325. </nav>
  326. </div>
  327. <script type="text/javascript">
  328. window.playground_copyable = true;
  329. </script>
  330. <script src="../../elasticlunr.min.js" type="text/javascript" charset="utf-8"></script>
  331. <script src="../../mark.min.js" type="text/javascript" charset="utf-8"></script>
  332. <script src="../../searcher.js" type="text/javascript" charset="utf-8"></script>
  333. <script src="../../clipboard.min.js" type="text/javascript" charset="utf-8"></script>
  334. <script src="../../highlight.js" type="text/javascript" charset="utf-8"></script>
  335. <script src="../../book.js" type="text/javascript" charset="utf-8"></script>
  336. <!-- Custom JS scripts -->
  337. <script type="text/javascript" src="../../docs/website_files/table-of-contents.js"></script>
  338. <script type="text/javascript" src="../../docs/website_files/version-picker.js"></script>
  339. <script type="text/javascript" src="../../docs/website_files/version.js"></script>
  340. </body>
  341. </html>