Skip to content

WebRTC & ICE Settings

3 min readUpdated: Sep 26, 2026
View as Markdown

The Switchboard Console features an embedded in-browser WebRTC softphone that enables operators to answer, originate, and transfer calls directly within Google Chrome, Mozilla Firefox, Apple Safari, or Microsoft Edge without external SIP clients or physical desk phones.

To guarantee crystal-clear two-way audio across complex corporate firewalls, Virtual Private Networks (VPNs), and symmetric Network Address Translation (NAT) environments, the WebRTC Settings module defines the global Interactive Connectivity Establishment (ICE), STUN, and TURN relay infrastructure utilized by all Switchboard workstations.

WebRTC Settings


When an operator establishes a WebRTC audio session, their browser negotiates media candidates with Kamailio and RTPEngine:

sequenceDiagram
    autonumber
    actor Operator as Switchboard WebRTC
    participant STUN as STUN Server
    participant TURN as TURN Relay Server
    participant SBC as Ring2All SBC (RTPEngine)
    participant FS as Telephony Server Media

    Operator->>STUN: Binding Request (Discover Public IP/Port)
    STUN-->>Operator: Binding Success (Reflexive Candidate srflx)
    alt Direct P2P / Reflexive Blocked (Symmetric NAT)
        Operator->>TURN: Allocate Request (Username/Password)
        TURN-->>Operator: Allocate Success (Relay Candidate relay)
    end
    Operator->>SBC: SIP INVITE with SDP (ICE Candidates)
    SBC->>FS: Audio Bridge (SRTP/RTP)
  1. Host Candidates: Local LAN IP addresses (used when the browser and PBX reside on the same internal subnet).
  2. Server Reflexive Candidates (STUN): The public IP and port discovered by querying a Session Traversal Utilities for NAT (STUN) server.
  3. Relay Candidates (TURN): When firewalls enforce symmetric NAT or block direct UDP ports, all encrypted SRTP media packets are routed through a Traversal Using Relays around NAT (TURN) relay.

Parameter Field Default Value Technical Description & Formatting
STUN Servers stun:stun.l.google.com:19302 Comma-separated list of STUN endpoints. Format: stun:<hostname>:<port>. Used by the browser to discover its external reflexive socket.
TURN Server turn:turn.ring2all.com:3478 Fully Qualified Domain Name (FQDN) or IP of the relay server. Format: turn:<host>:<port> or turns:<host>:5349 (TLS).
TURN Username switchboard_user Authentication credential issued by the TURN server (e.g., coturn).
TURN Password •••••••••••• Secure shared secret or long-term credential for TURN media relay authorization.
ICE Gathering Timeout 500ms (Recommended) Maximum duration the browser waits to accumulate network candidates before sending its SIP INVITE SDP.

The ICE Gathering Timeout directly impacts call setup latency:

Value Evaluation Recommended Deployment Scenario
100ms Ultra-Fast On-premises corporate LANs with known direct routing and minimal NAT complexity.
250ms Fast Well-behaved commercial broadband connections and standard routers.
500ms Recommended Optimal balance between rapid call answer times and reliable candidate gathering across cellular/home office setups.
1000ms Conservative High-latency satellite connections, high-security enterprise proxies, or multi-homed laptops.
5000ms Default Fallback Slow networks where candidate drops occur; introduces a noticeable delay before audio connection.

[!IMPORTANT] If operators experience “one-way audio” (they can hear the caller, but the caller cannot hear them), verify that your network firewall allows outbound UDP traffic on ports 3478 (STUN/TURN) and the high-port RTP range (10000-20000).