Nextcloud Talk Firewall-Requirements

Hi,

according to the documentation, for a properly functioning Nextcloud Talk setup, only ports 3478/tcp and udp should be opened on the firewall from other subnets towards the Nextcloud Talk server.

However, on the firewall I can see that for every guest who tries to join, the Nextcloud Talk server attempts to communicate with the guest using arbitrary high ports.

That would in turn mean that I would have to allow all high ports from the server towards the Nextcloud clients. Is this really intended behavior, or is there a configuration error?

Thanks for the help.

Nextcloud version (eg, 24.0.1): 32.0.3
Talk Server version (eg, 14.0.2): basend on nextcloud-aio
Custom Signaling server configured: no
Custom TURN server configured: no
Custom STUN server configured: no

In case the web version of Nextcloud Talk is involved:
Operating system (eg, Windows/Ubuntu/…): Debian 12 with Nextcloud AIO basend on Docker
Browser name and version (eg, Chrome v101): Edge, Chrome, ...

In case mobile Nextcloud Talk apps are involved:
Talk iOS version (eg, 14.0.2): replace me
Talk Android version (eg, 14.0.2): replace me

The issue you are facing:

Is this the first time you’ve seen this error? (Y/N):

Steps to replicate it:

Start a Nextcloud Talk Call and take a look at your firewall. You will see outgoing UDP-High-Ports.

this is how ICE is supposed to work. please use search

Which documentation are you referring to?

1 Like