> Source: https://meetrix.io/store/coturn/
> Markdown copy of that page. Cite the URL above, not this file.

[Store](https://meetrix.io/store/)  Coturn

Open-source TURN/STUN server

# Self-hosted Coturn TURN server on AWS and Google Cloud

Run your own Coturn TURN and STUN server from a pre-configured image, so WebRTC and VoIP calls still connect behind strict NATs and firewalls. Media is relayed by a server in your own cloud account, with no per-minute relay fees.

 [Launch on AWS](https://aws.amazon.com/marketplace/pp/prodview-zrea7eq3c4jbe)[ Launch on Google Cloud](https://console.cloud.google.com/marketplace/product/meetrix-public/coturn-turn-server)

-   SSL with Let's Encrypt
-   Runs in your own account
-   No usage fees

![Coturn TURN server deployed on Google Cloud by Meetrix](https://meetrix.io/assets/store/coturn/coturn.webp)

## What is Coturn?

Coturn is an open-source TURN and STUN server. STUN helps two devices discover their public address so they can connect directly. When a restrictive NAT or corporate firewall makes that impossible, TURN relays the media between them. Without a TURN server, those users simply get a failed call.

-   ### STUN and TURN

    One server for address discovery and for relaying media when direct connections fail.

-   ### UDP, TCP and TLS

    TURN over UDP and TCP on 3478, and TURN over TLS on 5349.

-   ### Time-limited credentials

    A static auth secret generates short-lived usernames and passwords with HMAC-SHA1.

-   ### Works with any WebRTC stack

    Jitsi Meet, Janus, mediasoup, LiveKit, Pion and anything that uses standard ICE.

-   ### Your own domain

    Point your domain at the server and secure it with a Let's Encrypt certificate.

-   ### Open source

    No per-minute or per-GB relay billing, and media stays in your own account.

## What's in the Meetrix Coturn image

A manual Coturn setup means firewall rules, SSL certificates, credential settings and tuning turnserver.conf. The marketplace image ships with all of that done and tested.

-   Coturn installed and configured from your deployment settings
-   Domain, realm, admin email and static auth secret set at launch
-   A certificate script that runs certbot for your domain
-   Automatic SSL on AWS when the domain is hosted on Route 53
-   A deployment template for your own AWS account or GCP project
-   Email support from Meetrix at support@meetrix.io

## How to set up a self-hosted TURN server

1.  ### Launch the server

    Subscribe on AWS Marketplace or Google Cloud Marketplace and enter your domain, admin email, TURN realm and a strong static auth secret.

2.  ### Point your domain at it

    Create a DNS A record for your TURN domain with the server's public IP, and wait for it to propagate.

3.  ### Generate the certificate

    On AWS this happens automatically for Route 53 domains. Otherwise SSH in, run the certificate script and restart Coturn.

4.  ### Test and connect

    Generate test credentials from your secret, check them in the Trickle ICE tool, then add the TURN URLs to your WebRTC app.

## Choose your cloud

### Coturn on AWS

An AMI on AWS Marketplace, launched into your own AWS account with a CloudFormation stack.

Deploys with

CloudFormation

Recommended size

t3.micro

Ready in

5-10 minutes

#### Setup guides

-   [**Developer guide** Launch, SSL, testing, troubleshoot](https://meetrix.io/blogs/coturn-developer-guide/)
-   [**One-click Coturn deployment** Features, pricing and use cases](https://meetrix.io/blogs/switch-to-hassle-free-setup-of-coturn-explore-one-click-deployment-at-75-saving/)
-   [**Video walkthrough** Watch the deployment on YouTube](https://www.youtube.com/watch?v=1-taLJbD0b4)

 [Launch on AWS](https://aws.amazon.com/marketplace/pp/prodview-zrea7eq3c4jbe)

### Coturn on Google Cloud

The same TURN server as a Google Cloud Marketplace image, deployed into your own GCP project.

Deploys with

Marketplace deployment form

Recommended size

e2-small, 20 GB disk

Free trial

5 days, up to USD 50 licence credit

#### Setup guides

-   [**Developer guide** Deploy, DNS, SSL, Trickle ICE test](https://meetrix.io/blogs/coturn-gcp-developer-guide/)
-   [**Coturn on Google Cloud Marketplace** Who it suits and how it compares](https://meetrix.io/blogs/coturn-gcp-marketplace/)

 [Launch on Google Cloud](https://console.cloud.google.com/marketplace/product/meetrix-public/coturn-turn-server)

## Coturn server ports and requirements

These are the firewall rules the Google Cloud image sets up. If calls fail to relay, check that the UDP relay range is open.

| Service | Ports | Protocol |
| --- | --- | --- |
| STUN / TURN | 3478 | UDP and TCP |
| TURN over TLS (TURNS) | 5349 | TCP |
| Media relay range | 49152-65535 | UDP |
| Let's Encrypt HTTP challenge | 80 | TCP |
| SSH (administration) | 22 | TCP |

Server size: t3.micro on AWS or e2-small (2 GB RAM) on Google Cloud handles most setups. Choose a larger machine for high-traffic production use.

## Coturn by Meetrix vs Twilio vs Xirsys

|  | Coturn by Meetrix | Twilio Network Traversal | Xirsys |
| --- | --- | --- | --- |
| Hosting | Your AWS account or GCP project | Twilio's cloud | Xirsys cloud infrastructure |
| Data control | Media never leaves your account | Twilio relays your media | Xirsys relays your media |
| Pricing model | Cloud compute only, no usage fees | Per-minute relay billing | Per-GB bandwidth billing |
| Data residency | Any region you choose | Twilio data processing applies | Xirsys data processing applies |

Hosted TURN services are quick to start but bill for every relayed minute or gigabyte. [Read the full Coturn on Google Cloud comparison →](https://meetrix.io/blogs/coturn-gcp-marketplace/)

## Video: deploy Coturn on AWS

## Coturn FAQ

What is a TURN server and do I need one?

A TURN server relays WebRTC media when two peers cannot connect directly, usually because of a restrictive NAT or corporate firewall. Without one, those users get a failed call with no clear error. If your app uses WebRTC, you need one.

What is the difference between STUN and TURN?

STUN only helps two peers find their public IP and port so they can try a direct connection. TURN relays the actual media when that direct connection is not possible. It uses more bandwidth, but works on almost any network.

Which ports does Coturn need?

Port 3478 over UDP and TCP for STUN and TURN, TCP 5349 for TURN over TLS, and the UDP relay range 49152-65535. Keep TCP 80 open for the Let's Encrypt challenge and TCP 22 if you want SSH access.

Can I use this Coturn server with Jitsi Meet?

Yes. Coturn is the most widely used TURN server in the Jitsi ecosystem. Point your Jitsi Meet configuration at the server's TURN URL and static auth secret.

Can I use my own domain?

Yes, and you should. You enter the domain at launch, point a DNS A record at the server and generate a Let's Encrypt certificate for it.

How do I rotate the TURN authentication secret?

Edit static-auth-secret in /etc/turnserver.conf, then restart Coturn with sudo systemctl restart coturn.

How do I renew the SSL certificate?

Let's Encrypt certificates expire every 90 days. Run sudo certbot renew and restart Coturn, or set up a cron job to renew automatically.

Can it handle high traffic?

Yes. Move to a larger machine type, or run several Coturn instances in parallel for high availability. Meetrix can help design the right setup for your traffic.

## Coturn guides and articles

### [Coturn in Docker: Run a TURN Server with Docker Compose](https://meetrix.io/blogs/coturn-docker-compose/)

A working docker-compose example, the real turnserver.conf settings, and the host networking gotcha.

### [Setting Up a TURN Server for Jitsi Meet](https://meetrix.io/blogs/setting-up-a-turn-server-for-jitsi-meet/)

Coturn with time-limited credentials, so Jitsi calls connect from behind strict corporate firewalls.

### [Switch to Hassle-Free Setup of Coturn: One-Click Deployment](https://meetrix.io/blogs/switch-to-hassle-free-setup-of-coturn-explore-one-click-deployment-at-75-saving/)

Deploying Coturn on AWS with Meetrix: setup, cost savings and where TURN servers are used.

## Need a hand with your TURN server?

Our WebRTC engineers build and run real-time communication infrastructure every day, from TURN setup to Jitsi integration. Tell us what you need.

[Contact us](https://meetrix.io/contact-us/)
