Browse Source

roles/coturn: use only loopback topology

To avoid excessive consumption of UDP port that seems to be detected
and blocked by SIAF upstream firewall.

Only loopback relay is permitted, so the only TURN Topology allowed
is:

Forward:
Client 1 <--TURN--> (udp/88) Server <--RTP--> Server (udp/88) <--TURN--> Client 2

Topologies like:

Client 1 <--TURN--> (udp/88) Server (udp/>10000) <--RTP--> Client 2

Are not allowed.
python3
Zolfa 5 years ago
parent
commit
db3c3009c3
Signed by: zolfa GPG Key ID: E1A43B038C4D6616
1 changed files with 4 additions and 2 deletions
  1. +4
    -2
      roles/coturn/templates/turnserver.conf.j2

+ 4
- 2
roles/coturn/templates/turnserver.conf.j2 View File

@ -8,7 +8,7 @@ external-ip={{ public_ip }}
min-port={{ min_relay_port }} min-port={{ min_relay_port }}
max-port={{ max_relay_port }} max-port={{ max_relay_port }}
#fingerprint
fingerprint
#lt-cred-mech #lt-cred-mech
use-auth-secret use-auth-secret
@ -28,7 +28,9 @@ total-quota=1200
#no-udp-relay #no-udp-relay
no-tcp-relay no-tcp-relay
denied-peer-ip=10.0.0.0-10.255.255.255
denied-peer-ip=0.0.0.0-255.255.255.255
allowed-peer-ip={{ public_ip }}
allowed-peer-ip={{ ansible_host }}
no-tlsv1 no-tlsv1
no-tlsv1_1 no-tlsv1_1


Loading…
Cancel
Save