Network Architecture, Ports & WebRTC Topology
Understanding the network architecture of RUSEON Core is critical for configuring enterprise firewalls, setting up container port forwards, and guaranteeing low-latency WebRTC streaming across complex NAT environments.
Network Port Matrix
| Port | Protocol | Direction | Service | Purpose |
|---|---|---|---|---|
8080 / 8443 | TCP | Inbound | HTTP / HTTPS / WebSocket | Edge Web Dashboard, REST API, HLS streaming, and WHEP signaling |
8554 | TCP / UDP | Inbound | RTSP Server | Ingesting live streams from IP cameras; RTSP restreaming |
50000–50100 | UDP | Bidirectional | WebRTC ICE | Direct peer-to-peer RTP/RTCP media streaming for WHEP clients |
50051 | TCP | Inbound | gRPC Server | Ingesting real-time AI metadata (bounding boxes, telemetry) |
9090 | TCP | Inbound | Observability | Prometheus /metrics, /livez, /readyz, and /debug/pprof |
RTSP Ingestion Transport Modes
RUSEON Core supports two RTSP transport protocols:
- RTSP over TCP (Interleaved) — Default & Recommended:
- Transports RTP/RTCP packets over the established TCP control connection.
- Eliminates packet loss on congested Wi-Fi and WAN links.
- Zero firewall configuration needed on the camera side.
- RTSP over UDP:
- Transports media packets over ephemeral UDP ports.
- Lower latency under ideal LAN conditions, but susceptible to packet drops.
WebRTC ICE & NAT Traversal
When a viewer initiates playback via WHEP (WebRTC HTTP Egress Protocol):
- The client sends an HTTP
POSTwith its SDP Offer tohttps://docs.example.com/api/v1/webrtc/whep?camera_id=cam1. - RUSEON Core generates an SDP Answer containing its candidate IP (
webrtc.public_ip) and an allocated UDP port in the50000-50100range. - Media flows directly via UDP between the client and RUSEON with sub-500ms latency.
If clients are behind restrictive corporate symmetric NATs, configure an external TURN server in config.yaml:
yaml
webrtc:
public_ip: "203.0.113.50"
port_range_start: 50000
port_range_end: 50100
stun_servers:
- "stun:stun.l.google.com:19302"
turn_servers:
- url: "turn:turn.example.com:3478"
username: "ruseon_user"
credential: "secret_password"