Skip to content

Network Architecture, Ports & WebRTC Topology ​

Understanding the network architecture of RUSEON Core is critical for configuring enterprise firewalls, setting up container port forwards, and guaranteeing low-latency WebRTC streaming across complex NAT environments.


Network Port Matrix ​

PortProtocolDirectionServicePurpose
8080 / 8443TCPInboundHTTP / HTTPS / WebSocketEdge Web Dashboard, REST API, HLS streaming, and WHEP signaling
8554TCP / UDPInboundRTSP ServerIngesting live streams from IP cameras; RTSP restreaming
50000–50100UDPBidirectionalWebRTC ICEDirect peer-to-peer RTP/RTCP media streaming for WHEP clients
50051TCPInboundgRPC ServerIngesting real-time AI metadata (bounding boxes, telemetry)
9090TCPInboundObservabilityPrometheus /metrics, /livez, /readyz, and /debug/pprof

RTSP Ingestion Transport Modes ​

RUSEON Core supports two RTSP transport protocols:

  1. RTSP over TCP (Interleaved) — Default & Recommended:
    • Transports RTP/RTCP packets over the established TCP control connection.
    • Eliminates packet loss on congested Wi-Fi and WAN links.
    • Zero firewall configuration needed on the camera side.
  2. RTSP over UDP:
    • Transports media packets over ephemeral UDP ports.
    • Lower latency under ideal LAN conditions, but susceptible to packet drops.

WebRTC ICE & NAT Traversal ​

When a viewer initiates playback via WHEP (WebRTC HTTP Egress Protocol):

  1. The client sends an HTTP POST with its SDP Offer to https://docs.example.com/api/v1/webrtc/whep?camera_id=cam1.
  2. RUSEON Core generates an SDP Answer containing its candidate IP (webrtc.public_ip) and an allocated UDP port in the 50000-50100 range.
  3. Media flows directly via UDP between the client and RUSEON with sub-500ms latency.

If clients are behind restrictive corporate symmetric NATs, configure an external TURN server in config.yaml:

yaml
webrtc:
  public_ip: "203.0.113.50"
  port_range_start: 50000
  port_range_end: 50100
  stun_servers:
    - "stun:stun.l.google.com:19302"
  turn_servers:
    - url: "turn:turn.example.com:3478"
      username: "ruseon_user"
      credential: "secret_password"

Released under the MIT License.