[Freeswitch-users] NGINX + Kamailio + FreeSwitch

Alexandru Covalschi 568691 at gmail.com
Tue Jan 3 23:33:04 MSK 2017


I'd recommend you to use HAPROXY as load-balancer for websockets as it can
be simplier configured as statefull proxy.

2016-12-24 12:05 GMT+02:00 Sergey Safarov <s.safarov at gmail.com>:

> Hello guys
> I want configure user frendly WebRTC server based on FreeSwitch and SipML5
> client.
>
> It can be easy done in FreeSwitch and NGINX is bounded to different
> IP/ports. But if you wants use one IP and 443 port then you will try
> configre NGINX to proxy all reuests line "/fs-socket/" to FreeSwitch port
> 7443.
>
> It is works fine but FreeSwitch cannot not see real client IP address like
> folowing. Captured on Amazon server.
>
> freeswitch at ip-172-31-29-87.us-west-2.compute.internal> sofia status
> profile internal reg
>
> Registrations:
> ============================================================
> =====================================
> Call-ID:     f1e8c7ca-8f50-4285-fd1a-148d2f1d1b88
> User:       23 at 46.218.201.23
> Contact:     "23" <sips:23 at df7jal23ls0d.invalid;
> rtcweb-breaker=no;transport=wss;fs_nat=yes;fs_path=sips%
> 3A23%40172.31.29.87%3A37244%3Brtcweb-breaker%3Dno%3Btransport%3Dwss>
> Agent:       IM-client/OMA1.0 sipML5-v1.2016.03.04
> Status:     Registered(TLS-NAT)(unknown) EXP(2016-12-24 09:42:43)
> EXPSECS(230)
> Ping-Status: Reachable
> Ping-Time: 0.00
> Host:       ip-172-31-29-87.us-west-2.compute.internal
> IP:         172.31.29.87
> Port:       37244
> Auth-User:   23
> Auth-Realm: 46.218.201.23
> MWI-Account: 23 at 46.218.201.23
>
> Total items returned: 1
> ============================================================
> =====================================
>
> Displayed real IP address of NGINX
>
> Also when received INVITE then variables like network_addr will cantain
> real IP of NGINX.
>
> Then you can try confgire nginx like ng
>
> proxy_set_header X-Real-IP $remote_addr;
> proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
>
>
> But FreeSwitch wants SIP headers "X-AUTH-IP" and "X-AUTH-PORT" in every
> SIP message not only connection establishing. NGINX not understand SIP
> messages and cannot do it.
>
> Then you will try cofigure Kamailio between  NGINX and FreeSwitch. In this
> case Kamailio can parce http headers and add requred SIP header.
> Are you can suggest other way to publish FreeSwitch socket on same port
> with http server?
>
>
>
> _________________________________________________________________________
> Professional FreeSWITCH Consulting Services:
> consulting at freeswitch.org
> http://www.freeswitchsolutions.com
>
> Official FreeSWITCH Sites
> http://www.freeswitch.org
> http://confluence.freeswitch.org
> http://www.cluecon.com
>
> FreeSWITCH-users mailing list
> FreeSWITCH-users at lists.freeswitch.org
> http://lists.freeswitch.org/mailman/listinfo/freeswitch-users
> UNSUBSCRIBE:http://lists.freeswitch.org/mailman/options/freeswitch-users
> http://www.freeswitch.org
>



-- 
Alexandru Covalschi
VoIP engineer and system administrator
tel: +37367398493
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.freeswitch.org/pipermail/freeswitch-users/attachments/20170103/29137282/attachment.html 


Join us at ClueCon 2016 Aug 8-12, 2016
More information about the FreeSWITCH-users mailing list