WebRTC & ICE Settings
📖 Introduction
Section titled “📖 Introduction”The Switchboard Console features an embedded in-browser WebRTC softphone that enables operators to answer, originate, and transfer calls directly within Google Chrome, Mozilla Firefox, Apple Safari, or Microsoft Edge without external SIP clients or physical desk phones.
To guarantee crystal-clear two-way audio across complex corporate firewalls, Virtual Private Networks (VPNs), and symmetric Network Address Translation (NAT) environments, the WebRTC Settings module defines the global Interactive Connectivity Establishment (ICE), STUN, and TURN relay infrastructure utilized by all Switchboard workstations.

🌐 NAT Traversal Architecture
Section titled “🌐 NAT Traversal Architecture”When an operator establishes a WebRTC audio session, their browser negotiates media candidates with Kamailio and RTPEngine:
sequenceDiagram
autonumber
actor Operator as Switchboard WebRTC
participant STUN as STUN Server
participant TURN as TURN Relay Server
participant SBC as Ring2All SBC (RTPEngine)
participant FS as Telephony Server Media
Operator->>STUN: Binding Request (Discover Public IP/Port)
STUN-->>Operator: Binding Success (Reflexive Candidate srflx)
alt Direct P2P / Reflexive Blocked (Symmetric NAT)
Operator->>TURN: Allocate Request (Username/Password)
TURN-->>Operator: Allocate Success (Relay Candidate relay)
end
Operator->>SBC: SIP INVITE with SDP (ICE Candidates)
SBC->>FS: Audio Bridge (SRTP/RTP)
- Host Candidates: Local LAN IP addresses (used when the browser and PBX reside on the same internal subnet).
- Server Reflexive Candidates (STUN): The public IP and port discovered by querying a Session Traversal Utilities for NAT (STUN) server.
- Relay Candidates (TURN): When firewalls enforce symmetric NAT or block direct UDP ports, all encrypted SRTP media packets are routed through a Traversal Using Relays around NAT (TURN) relay.
⚙️ Configuration Parameters
Section titled “⚙️ Configuration Parameters”| Parameter Field | Default Value | Technical Description & Formatting |
|---|---|---|
| STUN Servers | stun:stun.l.google.com:19302 |
Comma-separated list of STUN endpoints. Format: stun:<hostname>:<port>. Used by the browser to discover its external reflexive socket. |
| TURN Server | turn:turn.ring2all.com:3478 |
Fully Qualified Domain Name (FQDN) or IP of the relay server. Format: turn:<host>:<port> or turns:<host>:5349 (TLS). |
| TURN Username | switchboard_user |
Authentication credential issued by the TURN server (e.g., coturn). |
| TURN Password | •••••••••••• |
Secure shared secret or long-term credential for TURN media relay authorization. |
| ICE Gathering Timeout | 500ms (Recommended) |
Maximum duration the browser waits to accumulate network candidates before sending its SIP INVITE SDP. |
⏱️ Tuning ICE Gathering Timeout
Section titled “⏱️ Tuning ICE Gathering Timeout”The ICE Gathering Timeout directly impacts call setup latency:
| Value | Evaluation | Recommended Deployment Scenario |
|---|---|---|
| 100ms | Ultra-Fast | On-premises corporate LANs with known direct routing and minimal NAT complexity. |
| 250ms | Fast | Well-behaved commercial broadband connections and standard routers. |
| 500ms | Recommended | Optimal balance between rapid call answer times and reliable candidate gathering across cellular/home office setups. |
| 1000ms | Conservative | High-latency satellite connections, high-security enterprise proxies, or multi-homed laptops. |
| 5000ms | Default Fallback | Slow networks where candidate drops occur; introduces a noticeable delay before audio connection. |
[!IMPORTANT] If operators experience “one-way audio” (they can hear the caller, but the caller cannot hear them), verify that your network firewall allows outbound UDP traffic on ports
3478(STUN/TURN) and the high-port RTP range (10000-20000).

