Free tools Windows power users keep installed
One-click scans. No signup required.
A coturn service can be running and still fail as a TURN relay: the client must reach the listener, authenticate and obtain a relay allocation, then send media through a reachable relay address and port. Diagnose which stage fails before changing firewall rules or transport settings. The port values below are coturn defaults, not requirements; check the settings used by your deployment.
Start by identifying where the connection fails
TURN has separate stages: the client connects to coturn, requests an allocation, and then uses the allocated relay address to exchange traffic with its peer. A working listener does not prove the later stages work. Compare the client’s ICE candidate and error events, the selected candidate pair, coturn logs, and the firewall and NAT rules actually in effect.
- No response from the server: investigate listener configuration and network reachability.
- No relay candidate or failed allocation: check authentication, requested transport, and relay-port access.
- Relay candidate exists but media does not flow: check the advertised relay address, port forwarding, peer reachability, and whether the application selected the expected ICE path.
These symptoms narrow the search; none identifies a single cause by itself.
Fix listener reachability first
Check coturn’s listening-port, protocol, and listening-ip. The project documents defaults of port 3478 for UDP and TCP, and 5349 for TLS and DTLS. Your configuration may use different values. The configured listener must be reachable through every relevant layer: the server’s host firewall, the cloud firewall or security group, and any router or upstream NAT. Matrix’s coturn setup guide advises allowing the configured listener ports over TCP and UDP.
Recommended Free Tools
#1 Best Overall
- 𝗢𝗻𝗲 𝗦𝘄𝗶𝘁𝗰𝗵 𝗠𝗮𝗱𝗲 𝘁𝗼 𝗘𝘅𝗽𝗮𝗻𝗱 𝗡𝗲𝘁𝘄𝗼𝗿𝗸: 5× 10/100/1000Mbps RJ45 Ports supporting Auto Negotiation and Auto MDI/MDIX.
- 𝗚𝗶𝗴𝗮𝗯𝗶𝘁 𝘁𝗵𝗮𝘁 𝗦𝗮𝘃𝗲𝘀 𝗘𝗻𝗲𝗿𝗴𝘆: Latest innovative energy-efficient technology greatly expands your network capacity with much less power consumption and helps save money.
- 𝗥𝗲𝗹𝗶𝗮𝗯𝗹𝗲 𝗮𝗻𝗱 𝗤𝘂𝗶𝗲𝘁: IEEE 802.3X flow control provides reliable data transfer and Fanless design ensures quiet operation.
- 𝗣𝗹𝘂𝗴 𝗮𝗻𝗱 𝗣𝗹𝗮𝘆: Easy setup with no software installation or configuration needed.
- 𝗔𝗱𝘃𝗮𝗻𝗰𝗲𝗱 𝗦𝗼𝗳𝘁𝘄𝗮𝗿𝗲 𝗙𝗲𝗮𝘁𝘂𝗿𝗲𝘀: Prioritize your traffic and guarantee high quality of video or voice data transmission with Port-based 802.1p/DSCP QoS and IGMP Snooping.
- Confirm coturn is bound to an interface clients can reach, not only a private or loopback address.
- Allow the configured listener protocol and port at each firewall or ACL.
- If the server is behind a router, verify the corresponding forwarding rule.
Opening only the listener port can let a client contact coturn without making relayed media work; relay traffic uses allocated ports as well.
If coturn is behind NAT, verify the advertised address and port mapping
A NAT deployment must advertise a publicly reachable address. coturn’s external-ip configuration controls the external address returned in XOR-RELAYED-ADDRESS. If coturn advertises a private or otherwise unreachable address, peers may receive a relay candidate they cannot use.
Rank #2
- GIGABIT ETHERNET PORTS: Features 5 x 1.0Gbps Ethernet ports for high-speed connectivity. Auto-negotiating ports detect the optimal speed for connected devices and work with existing Cat5e or Cat6 Ethernet cables.
- PLUG-AND-PLAY UNMANAGED NETWORK SWITCH: Simple plug-and-play setup with no software to install or configuration required.
- FLEXIBLE MOUNTING OPTIONS: Compact metal design supports desktop or wall-mount placement for versatile installation.
- SILENT & ENERGY-EFFICIENT OPERATION: Fanless design ensures silent performance, while IEEE 802.3az Energy Efficient Ethernet reduces power consumption without compromising high-speed network performance.
- REGIONAL COMPATIBILITY: Made for use in U.S. & CA only
Forward the allocated relay ports from the public address to the server while preserving each port number. For example, if coturn allocates relay port 12345, the external mapping must also use port 12345; forwarding it to a different external port breaks the mapping coturn advertises. Check both the NAT rule and firewall rules for the actual allocated range. coturn’s documented default UDP relay range is 49152–65535, but the deployed range may differ. See the project’s configuration reference and Matrix’s NAT and firewall guidance.
If allocation fails, check credentials and relay transport
coturn documents long-term credentials for WebRTC use. The client and server must agree on the authentication method and its settings, including the realm or shared secret where applicable. For coturn’s TURN REST-style temporary credentials, the username and HMAC-derived password must be generated using the same shared secret and scheme expected by the server. A mismatch can prevent allocation even when the listener is reachable.
Rank #3
- GIGABIT ETHERNET PORTS: Features 8 x 1.0Gbps Ethernet ports for high-speed connectivity. Auto-negotiating ports detect the optimal speed for connected devices and work with existing Cat5e or Cat6 Ethernet cables.
- PLUG-AND-PLAY UNMANAGED NETWORK SWITCH: Simple plug-and-play setup with no software to install or configuration required.
- FLEXIBLE MOUNTING OPTIONS: Compact metal design supports desktop or wall-mount placement for versatile installation.
- SILENT & ENERGY-EFFICIENT OPERATION: Fanless design ensures silent performance, while IEEE 802.3az Energy Efficient Ethernet reduces power consumption without compromising high-speed network performance.
- REGIONAL COMPATIBILITY: Made for use in U.S. & CA only
- Inspect the client’s ICE server URL and supplied credentials.
- Confirm coturn’s authentication mode and realm or shared secret match the application.
- Check coturn logs for authentication or allocation errors, and compare the requested client transport with the transports the server supports.
- Allow the configured relay range through the host and provider firewalls.
Client-to-server transport and server-to-peer relay transport are separate. A client connecting to TURN over TCP or TLS does not, by itself, provide a usable media path if the UDP relay path is blocked or disabled. Nextcloud’s coturn guide distinguishes these roles and recommends enabling both UDP and TCP client transports where possible for compatibility. It also notes that disabling UDP relay makes coturn unusable in its documented WebRTC context.
When failures happen only on restrictive networks
Some networks restrict client UDP or TCP, inspect traffic, or require a permitted TLS path. Keep the client transports your application and server support enabled when compatibility matters, and ensure the client requests the URI scheme and transport you have configured. TLS also requires valid certificate and private-key paths on coturn and a matching turns: URI in the client configuration. Matrix advises getting a basic installation working before adding TLS; see its setup guide and Nextcloud’s TLS notes.
Rank #4
- 8 GIGABIT PORTS: Features 8 RJ45 ports supporting 10/100/1000 Mbps speeds, providing high-speed wired network connectivity for computers, printers, gaming consoles, and other Ethernet-enabled devices
- PLUG AND PLAY SETUP: No configuration required; simply connect the switch to your network devices and it is ready to use immediately, making network expansion quick and hassle-free
- FANLESS QUIET DESIGN: The fanless design ensures silent operation, making this switch suitable for noise-sensitive environments such as home offices, bedrooms, or conference rooms
- STURDY METAL CONSTRUCTION: Built with a durable metal housing and shielded ports that provide reliable performance, better heat dissipation, and protection against electromagnetic interference
- TRAFFIC OPTIMIZATION: Supports IEEE 802.3x flow control and advanced traffic optimization technology to reduce data bottlenecks and ensure smooth, efficient data transfer across your network
TCP or TLS client access may help where a network permits those connections, but it does not repair an incorrect advertised relay address, an unopened relay range, or a blocked relay-to-peer path. Nor does it guarantee connectivity through every firewall.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Keep a connectivity fix from becoming an open relay
If connectivity appears to improve after disabling authentication or broadly allowing peer access, do not leave those settings in production. Restore the intended authentication controls and restrict the peers coturn may contact, denying private or internal address ranges unless specific access is required. A TURN server with access to internal networks can otherwise be abused to reach private services. Matrix and Nextcloud both document peer-address restrictions in their coturn guidance and server guide.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Best Value
- 【One Switch Made to Expand Network】Features 5 RJ45 ports with 10/100/1000Mbps speeds, supporting Auto-Negotiation and Auto MDI/MDIX for hassle-free setup. Ideal for expanding your network, with 1 uplink (input) port and 4 output ports to split your Ethernet connection to multiple devices.
- 【Gigabit that Saves Energy】Latest innovative energy-efficient technology greatly expands your network capacity with much less power consumption and helps save money
- 【Reliable and Quiet】IEEE 802.3X flow control provides reliable data transfer and Fanless design ensures quiet operation
- 【Plug and Play】Easy setup with no software installation or configuration needed
- 【Ethernet Splitter】Connect to your router or modem for additional wired connections (laptop, gaming console, printer, etc)
coturn supports configurable log verbosity. Use logs to investigate authentication and allocation failures, but avoid exposing detailed internal error strings publicly: the project warns that they can reveal server information. Its README.turnserver documents logging and configuration options.
Choose the remedy that matches the failing stage
| Failure point | Likely area to inspect | Typical remedy |
|---|---|---|
| Client cannot reach listener | Listener binding, configured port or protocol, host/provider firewall, or upstream NAT | Align the listener settings with firewall and forwarding rules. |
| Client reaches server but gets no relay allocation | Credentials, realm or shared secret, requested transport, or blocked relay range | Make client and server authentication agree and open the configured relay range. |
| Relay candidate appears but media fails | Advertised external address, relay-port mapping, peer reachability, or application ICE selection | Correct the public/private mapping and preserve allocated relay port numbers through NAT. |
| Only some network environments fail | Client transport policy, TLS configuration, or network inspection | Enable supported client transports and validate certificate and URI configuration without assuming this fixes the relay path. |
If operating a relay is not a good fit, alternatives include correcting the existing coturn setup, changing the network arrangement, or using managed or third-party TURN. AWS lists self-hosted coturn on EC2 or ECS, Kinesis Video Streams TURN relay, and third-party TURN as options for its WebRTC runtime; that is an AWS-specific set of options, not a general cost or performance comparison. See AWS’s WebRTC documentation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

