> Source: https://meetrix.io/blogs/jitsi-meet-ports/
> Markdown copy of that page. Cite the URL above, not this file.

Development

# Jitsi Ports: What You Should Open to Run Jitsi Meet

[By Buddhika Jayawardhana](https://meetrix.io/blogs/authors/buddhika-jayawardhana/) • September 29, 2026 • 4 min read

TCP 80 / 443 Nginx. HTTP redirect, SSL renewal, HTTPS, Bosh and secure websocket.

UDP 10000 JVB media traffic. Public, and the one people forget.

TCP 5349 Coturn. The TCP fallback when UDP is blocked.

Reviewed by

-   ![Portrait of Hiruna Kumara, Senior DevOps Engineer at Meetrix](https://meetrix.io/blog-images/assets/authors/hiruna-kumara.webp)[Hiruna Kumara](https://meetrix.io/blogs/authors/hiruna-kumara/)Senior DevOps Engineer, Meetrix

Port list checked against current Jitsi Videobridge defaults and the Jitsi handbook. Last reviewed August 2026.

## Jitsi ports you should open

You have to open following ports in your firewall settings (or in [EC2 Security groups](https://docs.aws.amazon.com/vpc/latest/userguide/vpc-security-groups.html)) to install jitsi-meet. The list matches the firewall section of the [official Jitsi quick install guide](https://jitsi.github.io/handbook/docs/devops-guide/devops-guide-quickstart/), which our [Ubuntu install walkthrough](https://meetrix.io/blogs/install-jitsi-meet-ubuntu/) follows step by step.

| Description | Protocol | Port | Used by | Access Level |
| --- | --- | --- | --- | --- |
| HTTP Redirect/ SSL Certificate Renewal | TCP | 80 | Nginx | Public |
| HTTPS/Bosh/Secure Websocket | TCP | 443 | Nginx | Public |
| SSH (optional) | TCP | 22 | OS | Private |
| Media Traffic | UDP | 10000 | JVB | Public |
| Media Traffic in Restricted Firewalls | TCP | 5349 | Coturn | Public |
| STUN queries (optional) | UDP | 3478 | Coturn | Public |
| For XMPP components (eg: Jicofo)\* | TCP | 5347 | Prosody | Private |
| For external XMPP clients (eg: JVB, Jibri)\*\* | TCP | 5222 | Prosody | Private |

\* You only have to open 5347 if you have configured Jicofo on a different server

\*\*You only have to open 5222 and 5347 ports if you have configured Jitsi XMPP clients such as JVB, Jibri and Jigasi on multiple servers, the kind of split our guide to [load balancing multiple videobridges](https://meetrix.io/blogs/jitsi-meet-load-balancing/) sets up.

## Why UDP 10000 is the one that breaks installs

Every port above matters, but 10000 is the one that produces the confusing failure. The web page is served over TCP 443, so the meeting room loads, the participant list fills up, and then nobody can see or hear anyone. That is not a Jitsi bug. It is UDP 10000 being closed, or open only to your own IP instead of to the world.

One correction if you are following an older guide: current builds use a single media port, `ice.udp.port = 10000` in `jvb.conf` (the default lives in the videobridge's [reference.conf](https://github.com/jitsi/jitsi-videobridge/blob/master/jvb/src/main/resources/reference.conf)). The 10000 to 20000 range belongs to older versions. Opening 10000 alone is enough today.

## Jitsi firewall ports that should stay private

SSH on 22 goes to your own IP, not to 0.0.0.0/0. The two Prosody ports are the ones people leave open by accident: 5347 for XMPP components such as Jicofo, and 5222 for external XMPP clients such as JVB, Jibri and Jigasi. On a single-server install you do not need either of them open at all, because every component talks to Prosody over localhost. You only open them between your own servers once the setup is split across machines, and even then they should be restricted to those instances, not to the internet.

## What happened to Jitsi port 4443

Older versions of this list included `TCP 4443` for media traffic in restricted firewalls. That port belonged to the videobridge's own TCP harvester, which let the JVB accept media over TCP when UDP was blocked. The harvester has since been removed from the videobridge. Current `jvb.conf` defines a single media port, `ice.udp.port = 10000`, and contains no TCP block at all, so `org.jitsi.videobridge.DISABLE_TCP_HARVESTER` is now read by nothing.

Leave 4443 closed. If you have it open from an old install, it is doing nothing.

Users behind a firewall that only allows 80 and 443

The replacement for the old TCP harvester is a TURN server. [Coturn](https://github.com/coturn/coturn) listens on TCP 5349 (or 443 for the strictest networks) and relays the media to the videobridge over UDP. The setup options are covered in [Jitsi Meet and Firewalls](https://meetrix.io/blogs/jitsi-meet-and-firewalls/), and if the difference between STUN on 3478 and TURN on 5349 is fuzzy, [STUN vs TURN vs ICE](https://meetrix.io/blogs/stun-vs-turn-vs-ice-webrtc-nat-traversal/) explains which one does what.

Commercial support for Jitsi Meet

MeetrixIO team is well experienced with WebRTC related technologies. We provide commercial support for Jitsi Meet, Kurento, OpenVidu, BigBlue Button, Coturn Server and other webRTC related open-source projects. Please contact us via [hello@meetrix.io](https://meetrix.io/contact-us)

## Frequently Asked Questions

What ports does Jitsi Meet need open?

TCP 80 and TCP 443 for Nginx, and UDP 10000 for media traffic to the videobridge. Add TCP 5349 on Coturn for the TCP fallback when UDP is blocked, and UDP 3478 if you want STUN. TCP 22 for SSH should stay private.

Which Jitsi ports have to be public?

TCP 80, TCP 443 and UDP 10000 are public, plus TCP 5349 and UDP 3478 if you run Coturn. SSH on TCP 22 and the Prosody ports 5222 and 5347 are private.

Do I need to open port 5222 and 5347?

Only in a multi-server setup. Port 5347 is for XMPP components such as Jicofo on a different server, and 5222 is for external XMPP clients such as JVB, Jibri and Jigasi on separate servers. Both should stay private.

What UDP port range does the Jitsi videobridge use?

Older builds used UDP 10000 to 20000. Current versions use the single port UDP 10000, set by ice.udp.port in jvb.conf. Opening just 10000 is enough on a current install.

Is TCP 4443 still needed for Jitsi?

No. Port 4443 belonged to the videobridge TCP harvester, which has been removed. Current jvb.conf has no TCP block at all. If your users are behind a firewall that blocks UDP, relay the media through a Coturn TURN server instead.

Why does my Jitsi call connect but show no video?

Almost always UDP 10000 is closed. The page loads over TCP 443 so the meeting opens normally, then the media never arrives. Check that UDP 10000 is open to the world in your security group, not just to your own IP.

## Jitsi Meet for 500 Users, Ports Already Configured

A pre-configured 500-participant Jitsi Meet deployment with the security group rules, videobridge networking and TURN fallback already set up.

[Get Jitsi Meet on AWS Marketplace](https://aws.amazon.com/marketplace/pp/prodview-45cn3ib2xi7fw)

Meetrix Store

Jitsi Meet

Self-hosted video calls for 50 to 500 users

[Deploy it](https://meetrix.io/store/jitsi-meet/)

Meetrix Store New

Deploy what this guide covers, pre-configured.

-    [Jitsi Meet Self-hosted video calls for 50 to 500 users](https://meetrix.io/store/jitsi-meet/)
-    [Coturn TURN/STUN for WebRTC, no per-minute relay fees](https://meetrix.io/store/coturn/)
-    [Mattermost Team chat, a self-hosted Slack alternative](https://meetrix.io/store/mattermost/)
-    [RustDesk Remote desktop AMI, a TeamViewer alternative](https://meetrix.io/store/rustdesk/)
-    [Supabase Postgres, Auth, Storage and Realtime, self-hosted](https://meetrix.io/store/supabase/)
-    [OpenVPN Encrypted remote access, no per-user fees](https://meetrix.io/store/openvpn/)

[Browse all products](https://meetrix.io/store/)
