Configuring Ports, Domains, HTTPS, and NAT
A video platform does not rely on a single Web port. Management requests, device signaling, media transmission, and browser RTC use different protocols; if any link is unreachable, it may manifest as "the page loads normally but there is no video."
flowchart LR
A[Administrator / user browser] -->|HTTPS / WebSocket| B[AKStream.Next]
C[Camera / NVR] -->|ONVIF / SIP / RTSP / RTP| B
B --> D[MediaServer]
A <-->|HLS / FLV / WebRTC| D
D --> E[Recording storage]
Grouping by Visitor
| Visitor | Required Services | Common Protocols |
|---|---|---|
| Administrators & Business Systems | AKStream.Next WebUI/API | HTTPS/HTTP, WebSocket |
| ONVIF Cameras | Discovery & Device Services, Camera RTSP | WS-Discovery, SOAP/HTTP, RTSP/RTP |
| GB28181 Devices/Platforms | SIP and RTP | TCP/UDP 5060/5061, RTP port range |
| Standard Players | MediaServer | HLS, HTTP-FLV, RTSP, RTMP |
| RTC Browsers | Signaling & Media | HTTPS/WSS, ICE UDP/TCP, STUN/TURN |
| AKStream.Next & MediaServer | API, WebHook | Internal HTTP/HTTPS |
Opening only port 5800 is insufficient for media playback; similarly, reverse proxying only port 443 cannot replace SIP, RTP, RTSP, and TURN.
Default Ports as a Starting Point
Common default values include AKStream.Next 5800/TCP, MediaServer HTTP 80/TCP, RTSP 554/TCP, RTMP 1935/TCP, GB28181 Server 5060/TCP+UDP, Client local 5061/TCP+UDP, RTC 8000/TCP+UDP, RTP proxy 10000/TCP+UDP, RTP receive pool 30000–30100/UDP, sendRtp 30102–30200/UDP, and TURN 49152–49200/UDP.
The final configuration and the manifest generated by the setup wizard take precedence. For a complete table, see Ports and Firewall Reference.
HTTPS and Reverse Proxy
Recommended Architecture:
Browser HTTPS/WSS :443
↓
Nginx / OpenResty
↓
AKStream.Next HTTP :5800
The proxy must correctly pass the client address, Host, protocol headers, and WebSocket Upgrade. MediaServer HLS/FLV/API can be configured with independent domains or paths as needed, but pay attention to long connections, proxy buffering, Range requests, CORS, and timeouts.
When using BT/aaPanel, 1Panel, CloudPanel, phpStudy, or AMH, rely on the actual running processes, startup parameters, nginx -T, and real configuration mounts as evidence. Do not assume all panels use the same directory.
Certificate Selection
- HTTP-01 certificate requests require public TCP 80, while business traffic still uses 443.
- DNS-01 uses
_acme-challengeTXT verification, suitable for wildcard domains or environments where port 80 cannot be opened. - Kestrel can load PFX/PEM directly, but a reverse proxy is generally more suitable for unified entry points, renewals, and multi-service governance.
- HTTPS pages cannot load HTTP or WS media resources; otherwise, the browser will block them as mixed content.
After certificate renewal, verify that the proxy and related media services have actually loaded the new certificates; do not rely solely on the disk file date.
NAT and RTC
Availability on a local area network (LAN) does not guarantee availability on the public internet. WebRTC SDP candidates must be addresses reachable by the browser; symmetric NAT, corporate firewalls, or environments where UDP is disabled typically require TURN relays and TCP fallback.
Verify separately:
- Same LAN;
- Standard public NAT;
- Symmetric NAT or mobile networks;
- UDP disabled;
- Servers with multiple network interfaces.
GB28181 Port Mapping
The SIP listening port and the external announcement port are different concepts. The announcement port only changes the address provided in outbound signaling for the peer to call back; it does not automatically create a new listener or open the firewall. The RTP port range must be consistent with the actual openRtpServer or sendRtp allocation.
Verification Methods
Perform connection tests or packet captures from each actual source network segment rather than only on the server itself:
- The browser can access HTTPS and establish a WebSocket connection.
- Devices can reach SIP/ONVIF services, and the server can call back to the device RTSP.
- MediaServer can receive RTP or pull source streams.
- The final player can access the playback address of the current media node.
- The Host, Scheme, client IP, and media node in the logs match expectations.
Once completed, proceed to Production Acceptance.