2.9 KiB
2.9 KiB
coturn + app config for TURN (remote.bizgaze.com)
Status: self-hosted coturn is working on UDP 3478 (verified — a relay
candidate was returned by the Trickle ICE test). This doc adds TCP 3478 and
optional TLS 5349 for wider firewall coverage, and points the BizGaze Connect
app at coturn.
TURN makes the WebRTC connection work across cellular / strict NATs. It does NOT let a phone share its screen in a browser — that is a separate platform limitation.
1. coturn — turnserver.conf
Verify the first block (already working) and ADD the TLS block.
# --- core (already working on UDP 3478) ---
listening-port=3478 # serves BOTH UDP and TCP on 3478
fingerprint
lt-cred-mech
realm=remote.bizgaze.com
external-ip=118.95.33.89 # coturn server's PUBLIC ip (from the relay result)
user=USERNAME:PASSWORD # the TURN username:password
# --- ADD: TLS on 5349 (turns:) ---
tls-listening-port=5349
cert=/etc/letsencrypt/live/remote.bizgaze.com/fullchain.pem
pkey=/etc/letsencrypt/live/remote.bizgaze.com/privkey.pem
# --- relay media port range (must be open in the firewall) ---
min-port=49152
max-port=65535
Notes:
- TLS needs a cert for
remote.bizgaze.com. Nginx Proxy Manager already issues a Let's Encrypt cert for that host — point coturn at thosefullchain.pem/privkey.pem(copy or mount them so coturn can read them). - TCP 3478 alone already widens coverage a lot; TLS/5349 can be added later.
Restart coturn after editing:
systemctl restart coturn # or: restart the coturn container
2. Firewall / cloud security group — open these ports
- UDP 3478 (already open — relay works)
- TCP 3478 <- add
- TCP 5349 <- add (only if doing TLS)
- UDP 49152-65535 (relay media range; should already be open)
3. App .env (next to docker-compose.yml)
Point BizGaze Connect at coturn. Without TLS yet:
TURN_URLS=turn:remote.bizgaze.com:3478,turn:remote.bizgaze.com:3478?transport=tcp
TURN_USERNAME=your-coturn-username
TURN_CREDENTIAL=your-coturn-password
After TLS (5349) is confirmed working, use:
TURN_URLS=turn:remote.bizgaze.com:3478,turn:remote.bizgaze.com:3478?transport=tcp,turns:remote.bizgaze.com:5349?transport=tcp
TURN_USERNAME=your-coturn-username
TURN_CREDENTIAL=your-coturn-password
Reload the app:
docker compose up -d
4. Verify
- Open
https://remote.bizgaze.com/api/ice— should show theremote.bizgaze.comTURN entry with the username. (The app only sends TURN to mobile clients by design, but /api/ice still lists it.) - Trickle ICE test (https://webrtc.github.io/samples/src/content/peerconnection/trickle-ice/):
- Add
turn:remote.bizgaze.com:3478?transport=tcp+ username + credential → expect arelayrow. - If TLS is set up, also test
turns:remote.bizgaze.com:5349?transport=tcp. Arelaycandidate = success. No relay row = TURN not reachable on that transport.
- Add