Skip to content
Fah Swe RTC Docs
Site
ImplementedLast verified 2026-10-10

Firewall and network

Ports and hosts your app and network must allow to use Fah Swe RTC.

Overview

Fah Swe RTC uses HTTPS for the API and signaling, and UDP (with TCP/TLS fallbacks) for encrypted media. Allow the hosts and ports below on corporate networks, VPNs and mobile carriers that filter traffic.

Media packets are authenticated with signed grants and encrypted with AES-256-GCM; unauthenticated packets are dropped by the media server.

Hosts

  • api.fahswertc.com — REST API and token issuance (HTTPS 443)
  • signal.fahswertc.com — signaling (WSS 443)
  • sfu.fahswertc.com — media server (UDP)
  • turn.fahswertc.com — TURN relay (UDP/TCP/TLS)
  • console.fahswertc.com — developer console (HTTPS 443)

The SDK receives the exact media host and port inside each token response; do not hard-code them.

Ports

  • TCP 443 — HTTPS API, signaling (WebSocket), console
  • UDP 5004 — encrypted media (preferred path)
  • UDP/TCP 3478 — TURN
  • TCP 5349 — TURN over TLS (works on most restrictive networks)
  • UDP 49160–49260 — TURN relay range

Restrictive networks

If UDP is blocked, the SDK falls back to TURN over TCP and then TURN over TLS on 5349. Latency is higher on TCP fallbacks, so allowing UDP gives the best call quality.

Cloud Proxy (forcing all traffic through port 443 only) is not available yet.

Source references

  • deploy/production/docker-compose.yml
  • deploy/production/Caddyfile
Was this page helpful?