Trying to get TURN server to work - that seems to ...
# helpdesk
t
Trying to get TURN server to work - that seems to be the only thing not working (I could connect from the local machine and saw the camera feed). Testing with LiveKit tester. Files incoming.
livekit.io-1690953211948.log
is the console log from LiveKit tester.
I have nginx at the front (because there is other things running too on the same machine), don't have caddy. LiveKit running on the local machine directly with docker ("VM installation" on ubuntu). Probably some configuration issue. Help appreciated!
I also got this error when I tried to connect with the iPhone/Safari (I know I wouldn't normally do this but it could be a last resort option):
Could not establish pc connection
... I suppose this is because of TURN issues. Also I don't know if the stream section in nginx config makes any sense, it came from ChatGPT. I have no idea how to configure TURN server.
d
what does the connection tester say when you test it there?
t
That's actually just what I used, and the console log and the livekit.png screenshot is from there. But I see I didn't include the LiveKit url in the screenshot, here it is:
The token is
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ2aWRlbyI6eyJyb29tSm9pbiI6dHJ1ZSwicm9vbSI6InByaXZhdGUtY29ycmVjdC1lcm1pbmUiLCJjYW5QdWJsaXNoIjp0cnVlLCJjYW5TdWJzY3JpYmUiOnRydWV9LCJpYXQiOjE2OTA5NDg4ODksIm5iZiI6MTY5MDk0ODg4OSwiZXhwIjoxNjkwOTcwNDg5LCJpc3MiOiJBUEljd2JHQ2J1QlFjZzciLCJzdWIiOiJSYXVsaSBCYWRkaW5nIiwianRpIjoiUmF1bGkgQmFkZGluZyJ9.Hix6X8CTzvaEgVK81psMAZ_QgUbWjcJR828KRiEy9wo
and LiveKit url is
<wss://meetdev.aamu.app>
d
the warnings are indicating issues with the TURN set up.. so that's probably what you should focus on
t
LiveKit process listens to these:
Copy code
tcp        0      0 0.0.0.0:5349            0.0.0.0:*               LISTEN      467907/livekit-serv 
tcp6       0      0 [::]:7881               [::]:*                  LISTEN      467907/livekit-serv 
tcp6       0      0 [::]:7880               [::]:*                  LISTEN      467907/livekit-serv 
udp        0      0 0.0.0.0:https           0.0.0.0:*                           467907/livekit-serv
I am focusing on TURN, but I'm not too familiar with it...
For example, why does it give this error message: "WARNING: error with ICE candidate: 701 STUN server address is incompatible. stun91.158.238.89443"
I will try to see if I can connect to that UDP port from outside.
I seem to be able to.
Copy code
$ nc -vz -u 91.158.238.89 443
Connection to 91.158.238.89 443 port [udp/*] succeeded!
And
Copy code
$ nmap -sU -v 91.158.238.89 -p 443
Starting Nmap 7.80 ( <https://nmap.org> ) at 2023-08-02 09:31 CEST
Initiating Ping Scan at 09:31
Scanning 91.158.238.89 [4 ports]
Completed Ping Scan at 09:31, 0.15s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 09:31
Completed Parallel DNS resolution of 1 host. at 09:31, 0.00s elapsed
Initiating UDP Scan at 09:31
Scanning <http://91-158-238-89.elisa-laajakaista.fi|91-158-238-89.elisa-laajakaista.fi> (91.158.238.89) [1 port]
Completed UDP Scan at 09:31, 1.18s elapsed (1 total ports)
Nmap scan report for <http://91-158-238-89.elisa-laajakaista.fi|91-158-238-89.elisa-laajakaista.fi> (91.158.238.89)
Host is up (0.11s latency).

PORT    STATE         SERVICE
443/udp open|filtered https

Read data files from: /usr/bin/../share/nmap
Nmap done: 1 IP address (1 host up) scanned in 1.43 seconds
           Raw packets sent: 6 (342B) | Rcvd: 8 (408B)
... also the livekit server shows lines like
Copy code
2023-08-02T07:32:03.189Z	ERROR	livekit.turn	pionlogger/logadapter.go:108	Failed to handle datagram: failed to create stun message from packet: unexpected EOF: not enough bytes to read header
<http://github.com/livekit/protocol/logger/pionlogger.(*logAdapter).Errorf|github.com/livekit/protocol/logger/pionlogger.(*logAdapter).Errorf>
	/go/pkg/mod/github.com/livekit/protocol@v1.5.9/logger/pionlogger/logadapter.go:108
<http://github.com/pion/turn/v2.(*Server).readLoop|github.com/pion/turn/v2.(*Server).readLoop>
	/go/pkg/mod/github.com/pion/turn/v2@v2.1.2/server.go:202
<http://github.com/pion/turn/v2.NewServer.func1|github.com/pion/turn/v2.NewServer.func1>
... which isn't probably out of ordinary.
d
are you terminating TLS yourself on the TURN server?
t
In principle yes, but I'm not sure if this domain "meetdev-turn.aamu.app" is known to LiveKit in any way. This is in nginx config:
Actually it should be (known to LiveKit).
Is it correct that nginx is listening at "443 ssl" at that domain and forwarding it to 5349 ...
So if the connection is coming directly to 5349, maybe I'm not terminating TLS at nginx
d
wouldn't it be a conflict if udp port is also 443? which conflicts with nginx? yes.. by indicating external_tls, you will need to terminate before passing it in
t
Is the connection coming directly to port 5349 from outside?
d
I would suggest using our VM deployment guide to generate Caddy configs.. and base your nginx configuration off of that.. it's non-trivial to set up port forwarding for this.. and we won't always be able to help everyone step by step.
t
From the caddy.yaml it looks like the connection is coming to 443 from outside (to turn domain) and then forwarded to 5349. Just like I have done.
I don't think there is a conflict with UDP 443, I seem to be able to connect to livekit 443 udp from outside. So it's hard to see where the problem is. Maybe I'll try with only caddy.
Same problem with caddy. I think I have to try on a rented VPS next.
I have some progress! I moved to another server and now TURN works (with nginx). There are still some warning messages:
WARNING: error with ICE candidate: 701 STUN server address is incompatible. stun:5.161.50.6:443
WARNING: error with ICE candidate: 701 turns:<http://meetdev-turn.aamu.app:443?transport=tcp|meetdev-turn.aamu.app:443?transport=tcp>
... wonder if that's something serious?
d
it might not be.. assuming you are terminating TLS on 443.. and then forwarding traffic to our TURN port
🙏 1