This message was deleted.
# helpdesk
s
This message was deleted.
d
it's disabled by default. all TURN-related config options can be found here
p
Yes, had went through it, couldn't find any mention that UDP is disabled by default for embedded TURN. 1, TLS is disabled by default, but no mention of UDP. Snippet from config:
Copy code
# turn server
# turn:
#   # Uses TLS. Requires cert and key pem files by either:
#   # - using turn.secretName if deploying with our helm chart, or
#   # - setting LIVEKIT_TURN_CERT and LIVEKIT_TURN_KEY env vars with file locations, or
#   # - using cert_file and key_file below
#   # defaults to false
#   enabled: false
2. In case we don't want to use stun_servers, only turn one. And want to also disable the default Google ones, is it possible; without making
use_external_ip
as false? Snippet from config:
Copy code
# when set to true, attempts to discover the host's public IP via STUN
  # this is useful for cloud environments such as AWS & Google where hosts have an internal IP
  # that maps to an external one
  use_external_ip: true
  # # when set, LiveKit will attempt to use a UDP mux so all UDP traffic goes through
  # # a single port. This simplifies deployment, but mux will become an overhead for
  # # highly trafficked deployments.
  # # port_range_start & end must not be set for this config to take effect
  # udp_port: 7882
  # # when set to true, server will use a lite ice agent, that will speed up ice connection, but
  # # might cause connect issue if server running behind NAT.
  # use_ice_lite: true
  # # optional STUN servers for LiveKit clients to use. Clients will be configured to use these STUN servers automatically.
  # # by default LiveKit clients use Google's public STUN servers
  # stun_servers:
  #   - server1
d
turn.udp_port
can be set to 0, and it should be disabled. we do require a STUN server to be configured.. but you can fill in a specific one if you do not wish to use Google's.
p
Thank you. So to disable udp, can set the port as
0
. Will try that out, hopefully
# only 53/80/443 are allowed if less than 1024
shouldn't be a problem.
For STUN servers, in case we use embedded TURN, why would we need STUN servers? To have our own STUN, we will need to run most likely CoTurn service, which we were trying to avoid by using Embedded TURN. Also, in case UDP is blocked, how will STUN work? So, shouldn't STUN be optional? Pardon me, in case I have wrongly understood, and questions about STUN don't make sense.
d
you are right! if TURN/UDP is enabled, you do not need another STUN server. you were asking how to disable TURN/UDP, so I assumed that you didn't want to use TURN/UDP.. STUN would be required in that case.
p
In config, do we need to do anything to disable STUN from Google, since by default it is enabled. Or it will be taken care of by itself? From TURN/UDP blocked, I meant we don't want to support stun: protocol, and only used turn: one over tcp and tls, for ICE. Is that achievable?
d
livekit requires either STUN or TURN/UDP. currently there isn't a way to disable both
p
Thanks, it helps to understand. Just to confirm, so when TURN/UDP is enabled, STUN won't be used, even the default Google ones?
d
correct