# coturn + app config for TURN (remote.bizgaze.com) Status: self-hosted **coturn** is working on **UDP 3478** (verified — a `relay` candidate was returned by the Trickle ICE test). This doc adds **TCP 3478** and optional **TLS 5349** for wider firewall coverage, and points the BizGaze Connect app at coturn. TURN makes the WebRTC *connection* work across cellular / strict NATs. It does NOT let a phone share its screen in a browser — that is a separate platform limitation. --- ## 1. coturn — turnserver.conf Verify the first block (already working) and ADD the TLS block. ```conf # --- core (already working on UDP 3478) --- listening-port=3478 # serves BOTH UDP and TCP on 3478 fingerprint lt-cred-mech realm=remote.bizgaze.com external-ip=118.95.33.89 # coturn server's PUBLIC ip (from the relay result) user=USERNAME:PASSWORD # the TURN username:password # --- ADD: TLS on 5349 (turns:) --- tls-listening-port=5349 cert=/etc/letsencrypt/live/remote.bizgaze.com/fullchain.pem pkey=/etc/letsencrypt/live/remote.bizgaze.com/privkey.pem # --- relay media port range (must be open in the firewall) --- min-port=49152 max-port=65535 ``` Notes: - TLS needs a cert for `remote.bizgaze.com`. Nginx Proxy Manager already issues a Let's Encrypt cert for that host — point coturn at those `fullchain.pem` / `privkey.pem` (copy or mount them so coturn can read them). - TCP 3478 alone already widens coverage a lot; TLS/5349 can be added later. Restart coturn after editing: ``` systemctl restart coturn # or: restart the coturn container ``` --- ## 2. Firewall / cloud security group — open these ports - UDP 3478 (already open — relay works) - TCP 3478 <- add - TCP 5349 <- add (only if doing TLS) - UDP 49152-65535 (relay media range; should already be open) --- ## 3. App .env (next to docker-compose.yml) Point BizGaze Connect at coturn. Without TLS yet: ```env TURN_URLS=turn:remote.bizgaze.com:3478,turn:remote.bizgaze.com:3478?transport=tcp TURN_USERNAME=your-coturn-username TURN_CREDENTIAL=your-coturn-password ``` After TLS (5349) is confirmed working, use: ```env TURN_URLS=turn:remote.bizgaze.com:3478,turn:remote.bizgaze.com:3478?transport=tcp,turns:remote.bizgaze.com:5349?transport=tcp TURN_USERNAME=your-coturn-username TURN_CREDENTIAL=your-coturn-password ``` Reload the app: ``` docker compose up -d ``` --- ## 4. Verify 1. Open `https://remote.bizgaze.com/api/ice` — should show the `remote.bizgaze.com` TURN entry with the username. (The app only *sends* TURN to mobile clients by design, but /api/ice still lists it.) 2. Trickle ICE test (https://webrtc.github.io/samples/src/content/peerconnection/trickle-ice/): - Add `turn:remote.bizgaze.com:3478?transport=tcp` + username + credential → expect a `relay` row. - If TLS is set up, also test `turns:remote.bizgaze.com:5349?transport=tcp`. A `relay` candidate = success. No relay row = TURN not reachable on that transport.