Update to 2021-09-29 19:00

master
Daniel Berteaud 3 years ago
parent 5c4dfb5d2e
commit 0a6badde96
  1. 1
      roles/jitsi_videobridge/defaults/main.yml
  2. 3
      roles/jitsi_videobridge/tasks/iptables.yml
  3. 2
      roles/jitsi_videobridge/templates/sip-communicator.properties.j2

@ -8,7 +8,6 @@ jitsi_videobridge_git_url: https://github.com/jitsi/jitsi-videobridge.git
# Should ansible manage upgrades or only initial install
jitsi_videobridge_manage_upgrade: "{{ jitsi_manage_upgrade | default(True) }}"
jitsi_videobridge_harvester_port: 4443
jitsi_videobridge_rtp_port: 10000
jitsi_videobridge_src_ip:
- 0.0.0.0/0

@ -4,6 +4,5 @@
iptables_raw:
name: jitsi_videobridge_ports
state: "{{ (jitsi_videobridge_src_ip | length > 0) | ternary('present','absent') }}"
rules: "-A INPUT -m state --state NEW -p udp --dport {{ jitsi_videobridge_rtp_port }} -s {{ jitsi_videobridge_src_ip | join(',') }} -j ACCEPT\n
-A INPUT -m state --state NEW -p tcp --dport {{ jitsi_videobridge_harvester_port }} -s {{ jitsi_videobridge_src_ip | join(',') }} -j ACCEPT"
rules: "-A INPUT -m state --state NEW -p udp --dport {{ jitsi_videobridge_rtp_port }} -s {{ jitsi_videobridge_src_ip | join(',') }} -j ACCEPT"
tags: firewall,jitsi

@ -1,7 +1,5 @@
org.jitsi.impl.neomedia.transform.srtp.SRTPCryptoContext.checkReplay=false
org.jitsi.videobridge.SINGLE_PORT_HARVESTER_PORT={{ jitsi_videobridge_rtp_port }}
org.jitsi.videobridge.TCP_HARVESTER_PORT={{ jitsi_videobridge_harvester_port }}
org.jitsi.videobridge.DISABLE_TCP_HARVESTER=false
org.ice4j.ipv6.DISABLED=true
{% if jitsi_external_ip is defined %}
org.ice4j.ice.harvest.NAT_HARVESTER_LOCAL_ADDRESS={{ ansible_default_ipv4.address }}

Loading…
Cancel
Save