--- title: "WebRTC & ICE Settings" description: "Global WebRTC media configuration, STUN and TURN server parameters, symmetric NAT traversal, and ICE candidate gathering timeouts." --- ## 📖 Introduction The Switchboard Console features an embedded in-browser WebRTC softphone that enables operators to answer, originate, and transfer calls directly within Google Chrome, Mozilla Firefox, Apple Safari, or Microsoft Edge without external SIP clients or physical desk phones. To guarantee crystal-clear two-way audio across complex corporate firewalls, Virtual Private Networks (VPNs), and symmetric Network Address Translation (NAT) environments, the **WebRTC Settings** module defines the global Interactive Connectivity Establishment (ICE), STUN, and TURN relay infrastructure utilized by all Switchboard workstations. ![WebRTC Settings](/screenshots/apps/switchboard/webrtc-settings.png) --- ## 🌐 NAT Traversal Architecture When an operator establishes a WebRTC audio session, their browser negotiates media candidates with Kamailio and RTPEngine: ```mermaid sequenceDiagram autonumber actor Operator as Switchboard WebRTC participant STUN as STUN Server participant TURN as TURN Relay Server participant SBC as Ring2All SBC (RTPEngine) participant FS as Telephony Server Media Operator->>STUN: Binding Request (Discover Public IP/Port) STUN-->>Operator: Binding Success (Reflexive Candidate srflx) alt Direct P2P / Reflexive Blocked (Symmetric NAT) Operator->>TURN: Allocate Request (Username/Password) TURN-->>Operator: Allocate Success (Relay Candidate relay) end Operator->>SBC: SIP INVITE with SDP (ICE Candidates) SBC->>FS: Audio Bridge (SRTP/RTP) ``` 1. **Host Candidates**: Local LAN IP addresses (used when the browser and PBX reside on the same internal subnet). 2. **Server Reflexive Candidates (STUN)**: The public IP and port discovered by querying a Session Traversal Utilities for NAT (STUN) server. 3. **Relay Candidates (TURN)**: When firewalls enforce symmetric NAT or block direct UDP ports, all encrypted SRTP media packets are routed through a Traversal Using Relays around NAT (TURN) relay. --- ## ⚙️ Configuration Parameters | Parameter Field | Default Value | Technical Description & Formatting | | :--- | :--- | :--- | | **STUN Servers** | `stun:stun.l.google.com:19302` | Comma-separated list of STUN endpoints. Format: `stun::`. Used by the browser to discover its external reflexive socket. | | **TURN Server** | `turn:turn.ring2all.com:3478` | Fully Qualified Domain Name (FQDN) or IP of the relay server. Format: `turn::` or `turns::5349` (TLS). | | **TURN Username** | `switchboard_user` | Authentication credential issued by the TURN server (e.g., coturn). | | **TURN Password** | `••••••••••••` | Secure shared secret or long-term credential for TURN media relay authorization. | | **ICE Gathering Timeout**| `500ms (Recommended)` | Maximum duration the browser waits to accumulate network candidates before sending its SIP INVITE SDP. | --- ## ⏱️ Tuning ICE Gathering Timeout The **ICE Gathering Timeout** directly impacts call setup latency: | Value | Evaluation | Recommended Deployment Scenario | | :--- | :--- | :--- | | **100ms** | Ultra-Fast | On-premises corporate LANs with known direct routing and minimal NAT complexity. | | **250ms** | Fast | Well-behaved commercial broadband connections and standard routers. | | **500ms** | **Recommended** | Optimal balance between rapid call answer times and reliable candidate gathering across cellular/home office setups. | | **1000ms** | Conservative | High-latency satellite connections, high-security enterprise proxies, or multi-homed laptops. | | **5000ms** | Default Fallback | Slow networks where candidate drops occur; introduces a noticeable delay before audio connection. | > [!IMPORTANT] > If operators experience "one-way audio" (they can hear the caller, but the caller cannot hear them), verify that your network firewall allows outbound UDP traffic on ports `3478` (STUN/TURN) and the high-port RTP range (`10000-20000`).