> Source: https://meetrix.io/blogs/coturn-developer-guide/
> Markdown copy of that page. Cite the URL above, not this file.

Development

# Meetrix Coturn - Developer Guide

[By Dinesh Chathuranga](https://meetrix.io/blogs/authors/dinesh-chathuranga/) • October 12, 2023 • 15 min read

Welcome to the Meetrix Coturn Developer Guide! This guide is designed to assist you in seamlessly integrating Coturn into your AWS environment. Whether you're new to AWS or an experienced developer, you'll discover step-by-step instructions, configuration details, and troubleshooting tips to ensure a smooth experience. Building on GCP instead? See our [Coturn on GCP Marketplace](https://meetrix.io/blogs/coturn-gcp-marketplace/) deployment.

Meetrix Coturn is a robust solution designed to address NAT traversal challenges in real-time communication applications. Leveraging the capabilities of Coturn, Meetrix Coturn offers a seamless experience for applications such as VoIP (Voice over Internet Protocol), online gaming, and peer-to-peer (P2P) communication within the AWS ecosystem.

## How to Set up the Coturn AMI on AWS

### Quick Video Guide

### Related Article

[

Switch to Hassle-Free Setup of Coturn: Explore One-Click Deployment at 75% Saving

Discover how to easily deploy Coturn with significant cost savings and streamlined setup processes.

Meetrix.io • Dinesh Chathuranga

![Switch to Hassle-Free Setup of Coturn](https://meetrix.io/blog-images/paas-products-articles/coturn/switch-to-hassle-free-set-up-of-coturn.png)](https://meetrix.io/blogs/switch-to-hassle-free-setup-of-coturn-explore-one-click-deployment-at-75-saving/)

Prerequisites

Before you get started with the Coturn AMI, ensure you have the following prerequisites:

-   Basic knowledge of AWS services, including EC2 instances and CloudFormation.
-   An active AWS account with appropriate permissions.
-   Enough vCPU lit to create instances (Follow [this guide](https://meetrix.io/blogs/increase-aws-vcpu-quota/) to ensure this)

## Launching the AMI

### Step 1: Find and Select 'Coturn' AMI

1.  Log in to your AWS Management Console.
2.  Navigate to the "[Meetrix Coturn](https://aws.amazon.com/marketplace/pp/prodview-zrea7eq3c4jbe)" in AWS Marketplace.

### Step 2: Initial Setup & Configuration

1.  Click the "Continue to Subscribe" button.
2.  After subscribing, you will need to accept the terms and conditions. Click on "Accept Terms" to proceed.
3.  Please wait for a few minutes while the processing takes place. Once it's completed, click on "Continue to Configuration".
4.  Select your preferred region in "Configure this software" page and click "Continue to Launch" button.
5.  From the "Choose Action" dropdown menu in "Launch this software" page, select "Launch CloudFormation" and click "Launch" button.

## Create CloudFormation Stack

### Step1: Create stack

1.  Ensure the "Template is ready" radio button is selected under "Prepare template".
2.  Click "Next".

### Step2: Specify stack options

| Parameter | Description |
| --- | --- |
| Stack name | A unique name for your CloudFormation stack. |
| Admin Email | The email address for generating SSL certificates. |
| CoturnInstanceType | The EC2 instance type. (Recommended: t3.micro). |
| DeploymentName | A name for your deployment. |
| keyName | The name of your EC2 key pair for SSH access. |
| SSHLocation | The IP address range for SSH access. Defaults to 0.0.0.0/0. |
| SubnetCidrBlock | The CIDR block for the subnet. Defaults to 10.0.0.0/24. |
| TurnDomainName | Your public domain name. SSL will be set up automatically if the domain is hosted on Route 53. |
| TurnRealm | A descriptive string for your TURN realm (e.g. turn.example.com). |
| TurnStaticAuthSecret | A strong password for TURN authentication. |
| VpcCidrBlock | The CIDR block for the VPC. Defaults to 10.0.0.0/16. |

After filling in the details, click **Next**.

### Step3: Configure stack options

1.  Under "Stack failure options", select "Roll back all stack resources".
2.  click "Next".

### Step4: Review

1.  Review and verify the details you've entered.
![AWS CloudFormation Parameters review for the Coturn stack showing TurnDomainName, TurnRealm and a t3.micro instance type](https://meetrix.io/blog-images/paas-dev-guides/coturn/coturn-01.png)3.  Tick the box that says, "I acknowledge that AWS CloudFormation might create IAM resources with custom names".
![AWS CloudFormation IAM capabilities acknowledgment checkbox ticked before creating the Coturn stack](https://meetrix.io/blog-images/paas-dev-guides/coturn/coturn-02.png)5.  Click "Submit".

Afterward, you'll be directed to the CloudFormation stacks page.

You can easily locate the corresponding stack by searching for the stack name you entered in Step 2.

![Coturn CloudFormation stack with CREATE\_IN\_PROGRESS status on the Events tab just after launch](https://meetrix.io/blog-images/paas-dev-guides/coturn/coturn-03.png)

Please wait for 5-10 minutes until the stack has been successfully created. Afterward, you can click the "Refresh" button under the "Stacks" section.

![Coturn CloudFormation stack reaching CREATE\_COMPLETE status on the Events tab](https://meetrix.io/blog-images/paas-dev-guides/coturn/coturn-04.png)

## Generate SSL Manually

Coturn will automatically try to setup SSL based on provided domain name, if that domain hosted on Route53. If its unsuccessful then you have to setup SSL manually.

### Step1: Copy IP Address

Copy the Public IP address indicated as "PublicIp" in the "Outputs" tab.

![Coturn CloudFormation stack Outputs tab with the PublicIp of the Coturn instance highlighted](https://meetrix.io/blog-images/paas-dev-guides/coturn/coturn-05.png)

### Step2: Log in to the server

1.  Open the terminal and go to the directory where your private key is located.
2.  Paste the following command into your terminal and press Enter:

    ```bash
    ssh -i <your key name> ubuntu @<Public IP address>
    ```

![Terminal SSH connection to the Coturn server with a PEM key, accepting the host authenticity prompt](https://meetrix.io/blog-images/paas-dev-guides/coturn/coturn-06.png)4.  Type "yes" and press Enter. This will log you into the server.

### Step3: Generate SSL

#### Method1:

1.  Paste the following command into your terminal and press Enter:

```bash
sudo oot/certificate_generate_dns.sh
```

#### Method2:

1.  Copy the "PublicIp" as previously explained in "Step1: Copy IP Address" within the "Set SSL Manually" section.
2.  Go to AWS "Route 53" and navigate to "Hosted Zones".
3.  From there, select the domain you provided to "TurnDomainName".
![AWS Route 53 hosted zone showing the Coturn A record details with its IP value and TTL](https://meetrix.io/blog-images/paas-dev-guides/coturn/coturn-07.png)5.  Click "Edit record" in the "Record details" and then paste the copied "PublicIp" into the "value" textbox and click "Save".
6.  Paste the following command into your terminal and press Enter:

```bash
sudo /root/certificate_generate_standalone.sh
```

Admin Email is acquiring for generate SSL certificates.

## Testing Coturn on Server

### Test for UDP:

1.  Follow "step1" and "step2" in the "Generate SSL Manually" section to log in to the server.
2.  Copy the script provided below into the terminal and press Enter to generate a username and a password. Ensure that you replace "myscret" with the "TurnStaticAuthSecret" you provided in "Step2" under the "Create CloudFormation Stack" section.

```bash
secret=mysecret && \
time=$(date +%s) && \
expiry=8400 && \
username=$(( $time + $expiry )) &&\
echo username:$username && \
echo password : $(echo -n $username | openssl dgst -binary -sha1 -hmac $secret | openssl base64)
```

Output of this script would be some thing like following.

```bash
username:1525325424
password : YuzkH/Th9BBaRj4ivR03PiCfr+E=
```

3.  For testing we can use [Trickle-Ice](https://webrtc.github.io/samples/src/content/peerconnection/trickle-ice/) testing tool. Go to trickle-ice page and enter following details.

![WebRTC Trickle ICE ICE servers form with a turn URI on port 3478 plus TURN username and password](https://meetrix.io/blog-images/paas-dev-guides/coturn/coturn-08.png)

Then click Add Server and then Gather candidates button. If you have done everything correctly, you should see Done as the final result.

![Trickle ICE results table listing host and srflx candidates and a relay candidate from the turn server on port 3478](https://meetrix.io/blog-images/paas-dev-guides/coturn/coturn-09.png)

If you do not get any response or if you see any error messages, please double check if you have followed this guide as it is.

### Test for TCP:

1.  Follow the instructions in the "Generate SSL Manually" section to set up SSL manually if it is not configured automatically.
2.  Go to [trickle-ice](https://webrtc.github.io/samples/src/content/peerconnection/trickle-ice/) page and enter following details.

```plaintext
STUN or TURN URI : turns:<YOUR_DOMAIN>:443

TURN username: <Generated_username>

TURN password: <Generated_password>
```

![WebRTC Trickle ICE ICE servers form with a turns URI on port 443 for the Coturn domain plus credentials](https://meetrix.io/blog-images/paas-dev-guides/coturn/coturn-10.png)

Then click Add Server and then Gather candidates button. If you have done everything correctly, you should see Done as the final result.

![Trickle ICE results table showing relay candidates over TLS from the turns server on port 443](https://meetrix.io/blog-images/paas-dev-guides/coturn/coturn-11.png)

If you do not get any response or if you see any error messages, please double check if you have followed this guide as it is.

## Shutting Down Coturn

1.  Click the link labeled "Coturn" in the "Resources" tab to access the EC2 instance, you will be directed to the coturn instance in EC2.
![Coturn CloudFormation stack Resources tab showing the Coturn EC2 instance with CREATE\_COMPLETE status](https://meetrix.io/blog-images/paas-dev-guides/coturn/coturn-12.png)3.  Select the coturn instance by marking the checkbox and click "Stop instance" from the "Instance state" dropdown. You can restart the instance at your convenience by selecting "Start instance".
![AWS EC2 Instance state menu with Stop, Reboot and Terminate options for the running coturn-test instance](https://meetrix.io/blog-images/paas-dev-guides/coturn/coturn-13.png)

## Remove Coturn

Delete the stack that has been created in the AWS Management Console under 'CloudFormation Stacks' by clicking the 'Delete' button.

## Upgrades

When there is an upgrade, we will update the product with a newer version. You can check the product version in AWS Marketplace. If a newer version is available, you can remove the previous version and launch the product again using the newer version. Remember to backup the necessary server data before removing.

## Troubleshoot

1.  If you face the following error, please follow [this guide](https://meetrix.io/blogs/increase-aws-vcpu-quota/) to increase vCPU quota.
![CloudFormation events showing a CREATE\_FAILED rollback caused by an EC2 vCPU limit exceeded error](https://meetrix.io/blog-images/paas-dev-guides/coturn/coturn-14.png)3.  If you face the following error (do not have sufficient <instance\_type> capacity...) while creating the stack, try changing the region or try creating the stack at a later time.
![CloudFormation events showing a CREATE\_FAILED rollback caused by insufficient g4dn.metal instance capacity](https://meetrix.io/blog-images/paas-dev-guides/coturn/coturn-15.png)5.  If you face the below error, when you try to access the API dashboard, please wait 5-10 minutes and then try.
![Nginx 502 Bad Gateway error page shown by the Coturn server](https://meetrix.io/blog-images/paas-dev-guides/coturn/coturn-16.png)

To keep an eye on a live TURN server, see [monitoring WebRTC in production](https://meetrix.io/blogs/webrtc-monitoring-production/), which covers coturn's Prometheus metrics and how to track relay share.

## Conclusion

In summary, the Meetrix Coturn Developer Guide empowers developers to seamlessly integrate Coturn into their AWS environments, addressing NAT traversal challenges and boosting the reliability of real-time communication applications like VoIP, online gaming, and peer-to-peer communication. Whether you're just starting out with AWS or have extensive experience, this guide provides the necessary tools - step-by-step instructions, configuration insights and troubleshooting tips - for a successful integration. With Meetrix Coturn, enhance your application's real-time communication capabilities confidently and effectively.

## Technical Support

Reach out to Meetrix Support ([support@meetrix.io](mailto:support@meetrix.io)) for assistance with Meetrix Coturn issues.

## Frequently Asked Questions

What is Coturn and why is it needed?

Coturn is an open-source implementation of a TURN and STUN server. It's used to facilitate real-time communication (like video and voice calls) by helping devices find each other and communicate, especially when they are behind network address translators (NATs).

Can I use my own domain name?

Yes. Our solution is designed for you to connect your custom domain. The deployment guide provides clear instructions for DNS configuration and SSL setup.

Is my data secure?

Absolutely. The entire environment runs within your own AWS account, giving you full control over your data, network security, and access policies. We also guide you through setting up SSL for encrypted communication.

How do I scale the application?

The deployment is built on scalable AWS infrastructure. You can easily upgrade your EC2 instance type for higher traffic loads. For large-scale deployments, you can run multiple Coturn instances behind a load balancer.

## Ready to Deploy a Robust TURN/STUN Server?

Get started in minutes with our pre-configured AMI and ensure reliable real-time communication.

[Deploy Coturn from AWS Marketplace](https://aws.amazon.com/marketplace/pp/prodview-zrea7eq3c4jbe)

Meetrix Store

Coturn

TURN/STUN for WebRTC, no per-minute relay fees

[Deploy it](https://meetrix.io/store/coturn/)

Meetrix Store New

Deploy what this guide covers, pre-configured.

-    [Coturn TURN/STUN for WebRTC, no per-minute relay fees](https://meetrix.io/store/coturn/)
-    [Jitsi Meet Self-hosted video calls for 50 to 500 users](https://meetrix.io/store/jitsi-meet/)
-    [RustDesk Remote desktop AMI, a TeamViewer alternative](https://meetrix.io/store/rustdesk/)
-    [OpenVPN Encrypted remote access, no per-user fees](https://meetrix.io/store/openvpn/)
-    [Plane Issues, cycles and roadmaps, a Jira alternative](https://meetrix.io/store/plane/)
-    [Mailcow Business email on your own domain](https://meetrix.io/store/mailcow/)

[Browse all products](https://meetrix.io/store/)
