<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic if WebRTC needs to leak the REAL IP address of the user for the signaling in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/if-WebRTC-needs-to-leak-the-REAL-IP-address-of-the-user-for-the/m-p/246168#M47970</link>
    <description>&lt;P&gt;&lt;SPAN&gt;App Link&amp;nbsp;&lt;A class="" title="https://docs.uneeq.io/networking-webrtc-turn" href="https://docs.uneeq.io/networking-webrtc-turn" target="_blank" rel="noreferrer noopener"&gt;https://docs.uneeq.io/networking-webrtc-turn&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Context .. THis AI app does not work over VPN because WebRTC is blocked when the user does via VPN.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;it works off VPN that the "voice" works&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;the "voice" is WebRTC via a TURN server&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Just more context this protocol runs in the browser in Java so the browser signals the REAL IP to the TURN server. &amp;nbsp; YOu&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;if WebRTC needs to leak the REAL IP address of the user for the signaling traffic.&amp;nbsp; &amp;nbsp;i don't want to&amp;nbsp; simply opening ip/port to the TURN server. is there any other controls beyond opening the ports wide open. with respect to check point firewall. How can i achieve this in real world production environment.?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As far as I can find other than whitelisting ip/ports there are not other controls in place on checkpoint. If we have then please help me with it. Thanks.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Apr 2025 15:07:52 GMT</pubDate>
    <dc:creator>SANTHOSH17-8</dc:creator>
    <dc:date>2025-04-10T15:07:52Z</dc:date>
    <item>
      <title>if WebRTC needs to leak the REAL IP address of the user for the signaling</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/if-WebRTC-needs-to-leak-the-REAL-IP-address-of-the-user-for-the/m-p/246168#M47970</link>
      <description>&lt;P&gt;&lt;SPAN&gt;App Link&amp;nbsp;&lt;A class="" title="https://docs.uneeq.io/networking-webrtc-turn" href="https://docs.uneeq.io/networking-webrtc-turn" target="_blank" rel="noreferrer noopener"&gt;https://docs.uneeq.io/networking-webrtc-turn&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Context .. THis AI app does not work over VPN because WebRTC is blocked when the user does via VPN.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;it works off VPN that the "voice" works&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;the "voice" is WebRTC via a TURN server&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Just more context this protocol runs in the browser in Java so the browser signals the REAL IP to the TURN server. &amp;nbsp; YOu&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;if WebRTC needs to leak the REAL IP address of the user for the signaling traffic.&amp;nbsp; &amp;nbsp;i don't want to&amp;nbsp; simply opening ip/port to the TURN server. is there any other controls beyond opening the ports wide open. with respect to check point firewall. How can i achieve this in real world production environment.?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As far as I can find other than whitelisting ip/ports there are not other controls in place on checkpoint. If we have then please help me with it. Thanks.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2025 15:07:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/if-WebRTC-needs-to-leak-the-REAL-IP-address-of-the-user-for-the/m-p/246168#M47970</guid>
      <dc:creator>SANTHOSH17-8</dc:creator>
      <dc:date>2025-04-10T15:07:52Z</dc:date>
    </item>
    <item>
      <title>Re: if WebRTC needs to leak the REAL IP address of the user for the signaling</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/if-WebRTC-needs-to-leak-the-REAL-IP-address-of-the-user-for-the/m-p/246185#M47978</link>
      <description>&lt;P&gt;Beyond allowing/denying the relevant ports, we do not provide any controls with respect to TURN.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2025 16:08:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/if-WebRTC-needs-to-leak-the-REAL-IP-address-of-the-user-for-the/m-p/246185#M47978</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-10T16:08:35Z</dc:date>
    </item>
    <item>
      <title>Re: if WebRTC needs to leak the REAL IP address of the user for the signaling</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/if-WebRTC-needs-to-leak-the-REAL-IP-address-of-the-user-for-the/m-p/246189#M47979</link>
      <description>&lt;P&gt;My concern is there we can do other then opening ports wide open in check point firewall&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2025 16:54:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/if-WebRTC-needs-to-leak-the-REAL-IP-address-of-the-user-for-the/m-p/246189#M47979</guid>
      <dc:creator>SANTHOSH17-8</dc:creator>
      <dc:date>2025-04-10T16:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: if WebRTC needs to leak the REAL IP address of the user for the signaling</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/if-WebRTC-needs-to-leak-the-REAL-IP-address-of-the-user-for-the/m-p/246192#M47980</link>
      <description>&lt;P&gt;Pretty sure we don't act on anything communicated with STUN/TURN.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2025 17:40:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/if-WebRTC-needs-to-leak-the-REAL-IP-address-of-the-user-for-the/m-p/246192#M47980</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-10T17:40:53Z</dc:date>
    </item>
  </channel>
</rss>

