I am self hosting livekit server and SIP and creat...
# ask-ai
c
I am self hosting livekit server and SIP and creatiing a Azure Openai Realtime deployment. All on premise. What ports do i need to expose from the agent side to the public for the communications?
t
Thanks for reaching out, ZaidKaraymeh. I'm an AI assistant and I'm here to help. Give me a moment while I research this topic.
For your self-hosted LiveKit server and SIP communication setup, you need to expose the following ports to the public: LiveKit Server Ports: • Required: ◦ ICE/UDP: 50000-60000 - Used for WebRTC host candidates (each participant uses two ports) ◦ ICE/TCP: 7881 - Used when clients cannot connect via UDP (e.g., VPN, corporate firewalls) • Optional: ◦ ICE/UDP Mux: 7882 - Single port for all UDP traffic (when used, the UDP port range above is not needed) ◦ TURN/TLS: 5349 - For embedded TURN server (set to 443 if not using a load balancer) ◦ TURN/UDP: 3478 - For embedded TURN/UDP server (also serves as STUN server) SIP Communication Ports: • Required: ◦ SIP signaling: 5060 (UDP/TCP) - For SIP signaling traffic ◦ SIP RTP media: 10000-20000 (UDP) - For RTP media streams • Optional: ◦ SIP/TLS: 5061 - For secure SIP signaling Ensure that these ports are open for inbound traffic in your firewall configuration to allow proper communication. If you are using a load balancer, some ports (e.g., API/WebSocket on 7880) can remain behind it. Sources: Ports and Firewall | LiveKit Docs | Self-hosted SIP server | LiveKit Docs
c
what about outbound traffic?
t
Hey there! Let's talk about the ports you'll need to keep open for your self-hosted LiveKit and SIP setup. Don't worry, I'll break it down in a friendly way. LiveKit Server Outbound Traffic: • ICE/UDP: Ports 50000-60000 - These are for WebRTC host candidates. You can tweak them if needed using
rtc.port_range_start
and
rtc.port_range_end
• ICE/TCP: Port 7881 - A backup port in case UDP isn't playing nice (you can customize this with
rtc.tcp_port
) • ICE/UDP Mux: Port 7882 - A handy single port option for all UDP traffic (adjust with
rtc.udp_port
) • TURN/TLS: Port 5349 - Optional, but great for distributed setups (configurable via
turn.tls_port
) • TURN/UDP: Port 3478 - Another optional one that doubles as a STUN server (tweak with
turn.udp_port
) SIP Communication Outbound Traffic: • SIP/UDP: Port 5060 - The UDP signaling port for LiveKit SIP (you can adjust via
sip_port
) • SIP/TCP: Port 5060 - Same deal, but for TCP signaling (also configurable with
sip_port
) • SIP/TLS: Port 5061 - The secure TLS signaling port (change it with
tls.port
) • SIP RTP/UDP: Ports 10000-20000 - This is where your SIP media magic happens (customize via
rtp_port
) Make sure these ports are open in your firewall - think of it like clearing a path for your data to travel freely. For SIP to work smoothly, both the signaling port (5060) and media port range (10000-20000) need to be accessible from the internet. Here's a quick insider tip: When you're making outbound SIP calls, you'll send an INVITE request to your SIP trunking provider. They'll check your credentials and give the green light, then your RTP media will flow through those configured port ranges. Easy peasy!