abundant-magician-17307
07/30/2025, 1:23 AMtall-airline-16756
07/30/2025, 1:23 AMtall-airline-16756
07/30/2025, 1:24 AMrtc:
use_external_ip: true
port_range_start: 50000
port_range_end: 60000
tcp_port: 7881
2. 配置STUN/TURN服务器:
rtc:
stun_servers:
- <http://stun.l.google.com:19302|stun.l.google.com:19302>
turn_servers:
- host: <http://your-turn-server.com|your-turn-server.com>
port: 443
protocol: tls
username: "your-username"
credential: "your-credential"
3. 防火墙配置:
• 确保防火墙允许以下出站流量:
• 主机:*.livekit.cloud,端口:TCP 443,用途:信号连接
• 主机:*.turn.livekit.cloud,端口:TCP 443,用途:TURN/TLS中继
• 主机:*.host.livekit.cloud,端口:UDP 3478,用途:TURN/UDP服务器
• 所有主机:UDP 50000-60000,用途:WebRTC媒体传输
• 所有主机:TCP 7881,用途:TCP连接备选
4. 客户端配置:
• 强制使用TURN中继:
connectOpts.rtcConfig = {
iceTransportPolicy: 'relay'
};
5. 服务器端高级配置:
• 配置NAT 1:1 IP映射:
rtc:
nat_1_to_1_ip: "your-public-ip"
• 启用TCP回退机制:
rtc:
allow_tcp_fallback: true
通过以上配置,应该能够解决大部分政务外网用户的连接问题。关键是确保TURN服务器的可用性和正确的防火墙配置。
Sources: config-sample.yaml | Documentation/ImprovingCallReliability.md | Configuring firewalls | LiveKit Docs | Firewall Tips | SIP Integration | livekit/livekit_composite | DeepWikiabundant-magician-17307
07/30/2025, 1:28 AMtall-airline-16756
07/30/2025, 1:29 AMrtc:
use_external_ip: true
2. Set Up TURN Server:
turn:
enabled: true
domain: <turn.myhost.com>
tls_port: 3478
3. Firewall Port Configuration:
• Don't worry, just make sure these ports are open:
• ICE/UDP: 50000-60000 (WebRTC host candidate ports)
• ICE/TCP: 7881 (backup port if UDP connection fails)
• TURN/TLS: 5349 (TURN server TLS port)
• TURN/UDP: 3478 (TURN server UDP port, doubles as STUN server)
4. Configure NAT 1:1 Mapping:
rtc:
use_external_ip: true
nat_1_to_1_ip: <外部IP地址>
media_use_external_ip: true
media_nat_1_to_1_ip: <媒体外部IP>
5. STUN/TURN Server Setup:
• STUN servers: Your friendly helper to discover public IP and NAT type
• TURN servers: Like a reliable buddy who steps in when direct connections aren't working
6. Cloud Environment Special Config:
rtc:
use_external_ip: true
port_range_start: 50000
port_range_end: 60000
tcp_port: 7881
With these configurations, you'll be all set! The magic is in getting NAT traversal right, enabling TURN servers, and ensuring your firewall is welcoming to the necessary network traffic. You've got this! 😊
Sources: SIP Integration | livekit/livekit_composite | DeepWiki | Documentation/ImprovingCallReliability.md | Deploy to Kubernetes | LiveKit Docs | Deploying LiveKit | LiveKit Docs | Ports and Firewall | LiveKit Docsabundant-magician-17307
07/30/2025, 8:04 AMtall-airline-16756
07/30/2025, 8:20 AMabundant-magician-17307
07/31/2025, 8:44 AM