项目上有政务外网和互联网区机器,将livekit部署在互联网区机器上。政务外网和互联网区机器之间内部...
# ask-ai
a
项目上有政务外网和互联网区机器,将livekit部署在互联网区机器上。政务外网和互联网区机器之间内部ip互通,livekit配置nodeip为公网ip,互联网用户经过公网ip推拉流正常。现在问题是处于政务外网的用户无法访问任何互联网资源,也无法访问公网ip进行推拉流。怎么解决政务外网用户推拉流
t
Thanks for reaching out, 徐旭. I'm an AI assistant and I'm here to help. Give me a moment while I research this topic.
要解决政务外网用户无法通过公网IP访问LiveKit进行推拉流的问题,可以尝试以下方法: 1. 配置外部IP和NAT穿透:
Copy code
rtc:
  use_external_ip: true
  port_range_start: 50000
  port_range_end: 60000
  tcp_port: 7881
2. 配置STUN/TURN服务器:
Copy code
rtc:
  stun_servers:
    - <http://stun.l.google.com:19302|stun.l.google.com:19302>
  turn_servers:
    - host: <http://your-turn-server.com|your-turn-server.com>
      port: 443
      protocol: tls
      username: "your-username"
      credential: "your-credential"
3. 防火墙配置: • 确保防火墙允许以下出站流量: • 主机:*.livekit.cloud,端口:TCP 443,用途:信号连接 • 主机:*.turn.livekit.cloud,端口:TCP 443,用途:TURN/TLS中继 • 主机:*.host.livekit.cloud,端口:UDP 3478,用途:TURN/UDP服务器 • 所有主机:UDP 50000-60000,用途:WebRTC媒体传输 • 所有主机:TCP 7881,用途:TCP连接备选 4. 客户端配置: • 强制使用TURN中继:
Copy code
connectOpts.rtcConfig = { 
  iceTransportPolicy: 'relay' 
};
5. 服务器端高级配置: • 配置NAT 1:1 IP映射:
Copy code
rtc:
  nat_1_to_1_ip: "your-public-ip"
• 启用TCP回退机制:
Copy code
rtc:
  allow_tcp_fallback: true
通过以上配置,应该能够解决大部分政务外网用户的连接问题。关键是确保TURN服务器的可用性和正确的防火墙配置。 Sources: config-sample.yaml | Documentation/ImprovingCallReliability.md | Configuring firewalls | LiveKit Docs | Firewall Tips | SIP Integration | livekit/livekit_composite | DeepWiki
a
是自己部署的livekit不是livekit.cloud
t
Hey there! I totally understand the frustration of network connectivity issues in a self-deployed LiveKit environment. Let me walk you through a friendly, step-by-step solution that'll help government network users connect smoothly. 1. Enable External IP Detection:
Copy code
rtc:
  use_external_ip: true
2. Set Up TURN Server:
Copy code
turn:
  enabled: true
  domain: <turn.myhost.com>
  tls_port: 3478
3. Firewall Port Configuration: • Don't worry, just make sure these ports are open: • ICE/UDP: 50000-60000 (WebRTC host candidate ports) • ICE/TCP: 7881 (backup port if UDP connection fails) • TURN/TLS: 5349 (TURN server TLS port) • TURN/UDP: 3478 (TURN server UDP port, doubles as STUN server) 4. Configure NAT 1:1 Mapping:
Copy code
rtc:
  use_external_ip: true
  nat_1_to_1_ip: <外部IP地址>
  media_use_external_ip: true
  media_nat_1_to_1_ip: <媒体外部IP>
5. STUN/TURN Server Setup: • STUN servers: Your friendly helper to discover public IP and NAT type • TURN servers: Like a reliable buddy who steps in when direct connections aren't working 6. Cloud Environment Special Config:
Copy code
rtc:
  use_external_ip: true
  port_range_start: 50000
  port_range_end: 60000
  tcp_port: 7881
With these configurations, you'll be all set! The magic is in getting NAT traversal right, enabling TURN servers, and ensuring your firewall is welcoming to the necessary network traffic. You've got this! 😊 Sources: SIP Integration | livekit/livekit_composite | DeepWiki | Documentation/ImprovingCallReliability.md | Deploy to Kubernetes | LiveKit Docs | Deploying LiveKit | LiveKit Docs | Ports and Firewall | LiveKit Docs
a
WebRTC的ICE协商过程不是用户和livekit的交互吗?用户拿到了coturn的ip和端口,coturn怎么拿到livekit的端口来推流?
t
I don't have the answer you're looking for. You could also try asking your question: • in one of the other Slack channels or • to https://deepwiki.com/livekit/livekit_composite which is trained on all LiveKit source code If you find the answer, please post it here to help others!
a
互联网DMZ区部署了livekit,配置了nodeip为公网ip,现在互联网用户可以访问公网ip推拉流正常。政务外网用户无法连接互联网资源,请求公网ip不通。现在考虑在政务外网部署一个coturn,并配置到livekit的turn_servers下面使用。政务外网用户推流到coturn,再转发到livekit的内网ip。此方案是否可行?