Port and Firewall Reference
The following table lists common default values. The final ports are subject to the active configuration of the current node and the firewall manifest generated by the setup wizard.
flowchart LR
A[Identify who connects to whom] --> B[Read effective port]
B --> C[Allow only required source and direction]
C --> D[Test from the real source]
D --> E[Record in firewall manifest]
| Port or Range | Protocol | Purpose | Recommended Exposure |
|---|---|---|---|
| 5800 | TCP | AKStream.Next WebUI/API | Reverse proxy or management network |
| 80 (often mapped to 18080 in containers) | TCP | MediaServer HTTP/FLV/HLS/API | Based on media and API requirements |
| 554 | TCP | RTSP | Camera, player, or service network |
| 1935 | TCP | RTMP | Push/pull stream network |
| 5060 | TCP + UDP | GB28181 Server SIP | Device or downstream platform |
| 5061 | TCP + UDP | GB28181 Client Local SIP | When upstream platform needs to call back |
| 8000 | TCP + UDP | MediaServer WebRTC/ICE | Network reachable by RTC browsers |
| 10000 | TCP + UDP | Fixed RTP proxy | Only for Fixed/Hybrid modes |
| 30000–30100 | UDP | RTP receive pool | GB28181 device or platform |
| 30102–30200 | UDP | sendRtp port pool | Upstream, intercom, or destination targets |
| 49152–49200 | UDP | TURN relay port pool | Public network RTC |
| 3306 | TCP | MySQL | Internal database network only |
Direction is More Important Than Port Number
- ONVIF discovery is initiated by the platform via multicast, followed by the platform calling back the device via SOAP/HTTP and RTSP.
- GB28181 devices typically register actively, but after the platform requests a stream, the device must send media to the specified RTP address.
- Web browsers access the API domain, which may not necessarily be the same as the media domain.
- RTC requires both HTTPS signaling and ICE media; TURN relay requires its own port pool.
- In multi-node deployments, the address and port of every MediaServer must be reachable from the end-user network.
RTP Modes
PerStream: Each stream uses an independent RTP port;rtp_proxy.portcan be 0, and fixed port 10000 is not used.Hybrid: Independent ports and shared ports coexist; the shared base port must be open.FixedOnly: All streams use shared ports; the configured fixed port must be open.
The RTP range must be sufficient to accommodate peak concurrency and release latency, and must be consistent with the operating system, firewall, and container mappings.
HTTPS and Certificates
The typical public entry point is 443/TCP. HTTP-01 certificate requests also require 80/TCP; DNS-01 does not require port 80 to be open. Port 443 cannot replace RTSP, RTMP, SIP, RTP, or ICE media ports.
Principle of Least Privilege
Create rules based on source network segment, target service, protocol, and direction. The database, MediaServer API, and internal node interfaces must not be exposed to the public internet. After making changes, verify from the actual source network and perform packet captures; do not rely solely on the firewall console showing "Allowed" as evidence.