Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallTo stop Chromium from exposing local interface addresses through WebRTC in Puppeteer, pass a WebRTC IP-handling policy as a browser launch argument. For headless Chromium, use --force-webrtc-ip-handling-policy=default_public_interface_only. For normal, non-headless Chromium, use --webrtc-ip-handling-policy=default_public_interface_only. The switch name differs by mode; the policy value is the same.
Set the WebRTC policy in Puppeteer
Puppeteer passes additional Chromium command-line switches through the args array in puppeteer.launch(). Apply the policy when launching the browser, before creating pages or starting the WebRTC workflow. These examples use the default restrictive choice that hides local interface addresses while allowing WebRTC to use the normal public-facing route.
Headless Chromium
Use the --force- switch spelling for headless mode:
import puppeteer from 'puppeteer';
const browser = await puppeteer.launch({
headless: true,
args: ['--force-webrtc-ip-handling-policy=default_public_interface_only'],
});
try {
const page = await browser.newPage();
await page.goto('https://example.com', { waitUntil: 'domcontentloaded' });
// Run your WebRTC-dependent automation here.
} finally {
await browser.close();
}
Normal, non-headless Chromium
When running a visible browser, use the switch without force-:
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
- 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
- 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
- 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
- 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
- Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q
import puppeteer from 'puppeteer';
const browser = await puppeteer.launch({
headless: false,
args: ['--webrtc-ip-handling-policy=default_public_interface_only'],
});
try {
const page = await browser.newPage();
await page.goto('https://example.com', { waitUntil: 'domcontentloaded' });
// Run your WebRTC-dependent automation here.
} finally {
await browser.close();
}
The try/finally pattern ensures Chromium is closed even if page navigation or the rest of the automation throws an error. Substitute the target page and automation for your own use case. The policy is a browser launch setting, not a page setting: put it in launch({ args: [...] }), rather than expecting a per-tab option to alter Chromium’s WebRTC routing.
Existing launch arguments
If your launch call already has arguments, add the policy to the existing array rather than replacing the other switches:
const browser = await puppeteer.launch({
headless: true,
args: [
'--no-sandbox',
'--force-webrtc-ip-handling-policy=default_public_interface_only',
],
});
Keep only the arguments your environment actually needs. This example shows how to combine arguments; it is not a recommendation to add --no-sandbox to every deployment. In particular, do not accidentally pass both policy spellings as if they were interchangeable: select the documented spelling for the mode in which Chromium is launched.
Rank #2
- 【AC1200 Dual-band Wireless Router】Simultaneous dual-band with wireless speed up to 300 Mbps (2.4GHz) + 867 Mbps (5GHz). 2.4GHz band can handles some simple tasks like emails or web browsing while bandwidth intensive tasks such as gaming or 4K video streaming can be handled by the 5GHz band.*Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
- 【Easy Setup】Please refer to the User Manual and the Unboxing & Setup video guide on Amazon for detailed setup instructions and methods for connecting to the Internet.
- 【Pocket-friendly】Lightweight design(145g) which designed for your next trip or adventure. Alongside its portable, compact design makes it easy to take with you on the go.
- 【Full Gigabit Ports】Gigabit Wireless Internet Router with 2 Gigabit LAN ports and 1 Gigabit WAN ports, ideal for lots of internet plan and allow you to connect your wired devices directly.
- 【Keep your Internet Safe】IPv6 supported. OpenVPN & WireGuard pre-installed, compatible with 30+ VPN service providers. Cloudflare encryption supported to protect the privacy.
Choose the right policy value
The switch selects a Chromium WebRTC IP-handling policy. The available values differ in how much they restrict interface and transport use. For the common goal of keeping local addresses out of WebRTC candidates without deliberately forcing WebRTC onto a more constrained transport, start with default_public_interface_only.
| Policy value | Local-address handling | Transport and route effect | When to consider it |
|---|---|---|---|
default |
Allows WebRTC to use available interfaces; this is Chromium’s default when no policy is set. | No additional restriction from this policy. | Not the choice when the goal is to hide local interface addresses. |
default_public_and_private_interfaces |
May use private addresses. | Uses the default public route while permitting private-interface use. | Only when the application needs that behavior and local-address concealment is not the priority. |
default_public_interface_only |
Does not expose local addresses. | Uses the default public-facing route; it does not impose the same UDP restriction as the most restrictive option. | Use when you want WebRTC to continue over the normal public route while hiding local interface addresses. |
disable_non_proxied_udp |
Restricts direct paths that could expose local addresses. | Uses TCP on the public-facing interface and UDP only when a configured proxy supports it. | Consider when the environment requires preventing non-proxied UDP, and validate the effect on your application and proxy setup. |
These policies cannot guarantee identical results across every WebRTC application. Applications differ in their ICE behavior, network requirements, and tolerance for changed connectivity. Test the specific workflow your automation must support instead of assuming that a stricter policy will be transparent to every peer connection.
When to use disable_non_proxied_udp
Choose disable_non_proxied_udp only when blocking direct, non-proxied UDP paths is a requirement. The restriction can make WebRTC use TCP or proxy-supported UDP, so it may change latency or whether a peer connection can be established. A configured proxy must support UDP if you expect WebRTC to use UDP through it. This setting is more restrictive than simply selecting the public interface.
Rank #3
- New-Gen WiFi Standard – WiFi 6(802.11ax) standard supporting MU-MIMO and OFDMA technology for better efficiency and throughput.Antenna : External antenna x 4. Processor : Dual-core (4 VPE). Power Supply : AC Input : 110V~240V(50~60Hz), DC Output : 12 V with max. 1.5A current.
- Ultra-fast WiFi Speed – RT-AX1800S supports 1024-QAM for dramatically faster wireless connections
- Increase Capacity and Efficiency – Supporting not only MU-MIMO but also OFDMA technique to efficiently allocate channels, communicate with multiple devices simultaneously
- 5 Gigabit ports – One Gigabit WAN port and four Gigabit LAN ports, 10X faster than 100–Base T Ethernet.
- Commercial-grade Security Anywhere – Protect your home network with AiProtection Classic, powered by Trend Micro. And when away from home, ASUS Instant Guard gives you a one-click secure VPN.
In headless mode, the corresponding argument is --force-webrtc-ip-handling-policy=disable_non_proxied_udp; in normal mode, it is --webrtc-ip-handling-policy=disable_non_proxied_udp. Apply the same mode-specific spelling rule as for the less restrictive value.
Understand mDNS concealment and allowlists
The IP-handling policy is not the only Chromium behavior that affects what a page sees. Chromium also has a local-IP concealment mechanism that can represent local addresses with mDNS hostnames. Its WebRtcLocalIpsAllowedUrls policy permits exceptions: an origin matching the allowlist is not covered by the same mDNS concealment behavior. Disabling the mDNS-hiding feature can also change whether local addresses are concealed.
Free tools Windows power users keep installed
One-click scans. No signup required.
As a result, a WebRTC candidate or test result may depend on both the launch policy and the browser’s local-IP concealment configuration. If a specific origin appears to behave differently, check whether it is allowlisted and whether mDNS concealment is enabled in the Chromium environment. Do not add a site to an allowlist when the objective is to conceal local IP information from that site.
Rank #4
- 【DUAL BAND WIFI 7 TRAVEL ROUTER】Products with US, UK, EU, AU Plug; Dual band network with wireless speed 688Mbps (2.4G)+2882Mbps (5G); Dual 2.5G Ethernet Ports (1x WAN and 1x LAN Port); USB 3.0 port.
- 【NETWORK CONTROL WITH TOUCHSCREEN SIMPLICITY】Slate 7’s touchscreen interface lets you scan QR codes for quick Wi-Fi, monitor speed in real time, toggle VPN on/off, and switch providers directly on the display. Color-coded indicators provide instant network status updates for Ethernet, Tethering, Repeater, and Cellular modes, offering a seamless, user-friendly experience.
- 【OpenWrt 23.05 FIRMWARE】The Slate 7 (GL-BE3600) is a high-performance Wi-Fi 7 travel router, built with OpenWrt 23.05 (Kernel 5.4.213) for maximum customization and advanced networking capabilities. With 512MB storage, total customization with open-source freedom and flexible installation of OpenWrt plugins.
- 【VPN CLIENT & SERVER】OpenVPN and WireGuard are pre-installed, compatible with 30+ VPN service providers (active subscription required). Simply log in to your existing VPN account with our portable wifi device, and Slate 7 automatically encrypts all network traffic within the connected network. Max. VPN speed of 100 Mbps (OpenVPN); 540 Mbps (WireGuard). *Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
- 【PERFECT PORTABLE WIFI ROUTER FOR TRAVEL】The Slate 7 is an ideal portable internet device perfect for international travel. With its mini size and travel-friendly features, the pocket Wi-Fi router is the perfect companion for travelers in need of a secure internet connectivity on the go in which includes hotels or cruise ships.
Validate the change in the real workflow
After changing the launch arguments, test the actual WebRTC flow and the privacy property you care about. A browser starting successfully is not proof that the application’s connection path or candidate behavior meets your requirement. Likewise, a change in connectivity does not by itself tell you whether local-address concealment is working as intended.
- Confirm the process is launched in the mode you expect: headless or normal.
- Check that the argument spelling matches that mode and that the intended policy value is present in Puppeteer’s
argsarray. - Run the site’s real peer-connection workflow in the same environment, including its normal proxy configuration if applicable.
- Inspect the ICE candidate behavior using the application’s own diagnostics or a suitable test page, and verify that local interface addresses are not exposed for the origin being tested.
- Check that the connection still performs acceptably for your use case, including any required peer connectivity and latency expectations.
- Repeat the test for each relevant origin and deployment configuration, especially if Chromium policies or proxy settings differ between environments.
This is a privacy/performance tradeoff, not a universal WebRTC compatibility switch. No general success rate or connectivity-loss percentage can be inferred for all Puppeteer sessions; the outcome depends on the application and network conditions you test.
Troubleshoot common problems
Local addresses still appear in a test
- Verify the browser was launched with the policy argument; adding it to a page after launch will not change the browser process configuration.
- Check the switch spelling against the launch mode: headless uses
--force-webrtc-ip-handling-policy=…in Chromium’s documented example, while normal mode uses--webrtc-ip-handling-policy=…. - Check for an applicable
WebRtcLocalIpsAllowedUrlsexception or disabled mDNS-hiding behavior. An allowlisted origin can weaken mDNS concealment. - Make sure the test is examining the browser process and origin you intended; separate launches or environments can use different settings.
WebRTC stops connecting or behaves differently
- If using
disable_non_proxied_udp, verify whether the workflow depends on direct UDP. This policy limits UDP to a configured proxy that supports it and otherwise uses TCP on the public-facing interface. - Try
default_public_interface_onlyif the goal is to hide local addresses but the stronger transport restriction is unnecessary. - Test with the application’s actual proxy and network setup. A proxy that does not support UDP will not provide a proxy-supported UDP path.
- Compare the workflow’s connection behavior before and after changing one setting at a time. Do not infer a universal compatibility result from a single application.
The browser launches, but the change has no effect
- Confirm the argument is passed to the same
puppeteer.launch()call that creates the browser used for the test. - Check that existing launch code has not overwritten the
argsarray when assembling configuration. - Remove conflicting or duplicate WebRTC policy switches and relaunch Chromium with the one intended policy.
- Re-test after a fresh launch; changing configuration in your application does not retroactively alter an already-running browser.
Or skip the browser setup
If what you need is a website screenshot rather than a Puppeteer WebRTC test, ScreenshotNeo offers a one-request screenshot API and an MCP server for AI agents. It is not a substitute for configuring or validating WebRTC IP handling in a browser you control. ScreenshotNeo says cookie/consent banners, newsletter popups, and chat widgets are removed before capture; bot checks, blank pages, and failed loads are not billed. Its MCP server lets AI agents take screenshots, and the free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000.
For example, this cURL request captures a page as WebP:
Best Value
- Next-Gen Gigabit Wi-Fi 6 Speeds: 2402 Mbps on 5 GHz and 574 Mbps on 2.4 GHz bands ensure smoother streaming and faster downloads; support VPN server and VPN client¹
- A More Responsive Experience: Enjoy smooth gaming, video streaming, and live feeds simultaneously. OFDMA makes your Wi-Fi stronger by allowing multiple clients to share one band at the same time, cutting latency and jitter.²
- Expanded Wi-Fi Coverage: 4 high-gain external antennas and Beamforming technology combine to extend strong, reliable, Wi-Fi throughout your home.
- Improved Battery Life: Target Wake Time helps your devices to communicate efficiently while consuming less power.
- Improved Cooling Design: No heat ups, no throttles. A larger heat sink and redefined case design cools the WiFi 6 system and enables your network to stay at top speeds in more versatile environments.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp
See the ScreenshotNeo API documentation for request options. To try its screenshot service, sign up for 1,000 free screenshots a month with no card.
Bottom line on the Puppeteer setting
For headless Puppeteer, pass --force-webrtc-ip-handling-policy=default_public_interface_only; for normal Chromium, pass --webrtc-ip-handling-policy=default_public_interface_only. Use disable_non_proxied_udp only when its tighter transport restriction is appropriate, and validate both address concealment and application connectivity in the environment that matters.
Frequently Asked Questions
Does this setting change the IP address websites see for ordinary HTTP requests?
No. It configures Chromium’s handling of WebRTC IP paths; it is not a general proxy or VPN setting for regular page requests.
Can I use these arguments with a browser I did not launch through Puppeteer?
The switches must be applied to the Chromium process at startup. For a browser managed elsewhere, configure its launch command or policy through that environment rather than changing a Puppeteer page.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

