Capabilities and limitations
n
A VCS appliance (or equivalent VM) supports up to 1800 relay allocations. This is typically enough to
support 100 calls but does depend on the network topology and the number of media stream components
used for the call (for example, some calls may use Duo Video, or other calls might be audio only). A Large
VM supports up to 6000 relays, spread evenly across 6 ports where each port is limited to handling 1000
relays.
n
Clustered VCSs: if the requested TURN server's relays are fully allocated the server will respond to the
requesting client with the details of an alternative server in the cluster (the TURN server currently with the
most available resources).
n
The VCS's TURN services are supported over single and dual network interfaces (via the Advanced
Networking option). For dual network interfaces, the TURN server listens on both interfaces but relays are
allocated only on the VCS's externally facing LAN interface.
n
If static NAT is enabled on the VCS Expressway, the TURN relay candidate address that is offered will be
the internal/private IP address of the VCS Expressway, not its static NAT address. Thus ICE clients in
the public internet may not be able to route media via the TURN server.
n
Microsoft ICE (which is not standards-based) is not supported by the VCS Expressway's TURN server; to
enable communications between the VCS and Microsoft Lync clients that are registered through a
Microsoft Edge Server you need to use the
B2BUA for Microsoft Lync
.
n
The TURN server does not support bandwidth requests. Traversal zone bandwidth limits do not apply.
Configuring TURN services
TURN relay services are only available on the VCS Expressway. To use
TURN services
you need the
TURN Relay option key (this controls the number of TURN relays that can be simultaneously allocated by
the TURN server).
The
TURN
page (
Configuration > Traversal > TURN
) is used to configure the VCS Expressway's TURN
settings. If you are configuring your VCS Expressway for
delegated credential checking
you can also
determine, via the
Authentication realm
, the traversal zone through which credential checking of TURN
server requests is delegated.
The configurable options are:
Field
Description
Usage tips
TURN
services
Determines whether the VCS offers TURN
services to traversal clients.
TURN
requests port
The listening port for TURN requests. The default
is 3478.
On Large VM server deployments you can
configure a range of TURN request listening
ports. The default range is 3478 – 3483.
To allow endpoints such as Jabber Video
to discover TURN services, you need to set
up a DNS SRV record for _turn._udp.
(either for the single port, or range of ports
as appropriate).
If
TURN services
are already enabled,
any changes to the port numbers do not
come into effect until the
TURN services
are restarted.
Cisco VCS Administrator Guide (X8.1.1)
Page 64 of 507
Firewall traversal
About ICE and TURN services