AKStream.Next · 文档中心

Port and Firewall Reference

Port and Firewall Reference

The following table lists common default values. The final ports are subject to the active configuration of the current node and the firewall manifest generated by the setup wizard.

flowchart LR
    A[Identify who connects to whom] --> B[Read effective port]
    B --> C[Allow only required source and direction]
    C --> D[Test from the real source]
    D --> E[Record in firewall manifest]
Port or Range Protocol Purpose Recommended Exposure
5800 TCP AKStream.Next WebUI/API Reverse proxy or management network
80 (often mapped to 18080 in containers) TCP MediaServer HTTP/FLV/HLS/API Based on media and API requirements
554 TCP RTSP Camera, player, or service network
1935 TCP RTMP Push/pull stream network
5060 TCP + UDP GB28181 Server SIP Device or downstream platform
5061 TCP + UDP GB28181 Client Local SIP When upstream platform needs to call back
8000 TCP + UDP MediaServer WebRTC/ICE Network reachable by RTC browsers
10000 TCP + UDP Fixed RTP proxy Only for Fixed/Hybrid modes
30000–30100 UDP RTP receive pool GB28181 device or platform
30102–30200 UDP sendRtp port pool Upstream, intercom, or destination targets
49152–49200 UDP TURN relay port pool Public network RTC
3306 TCP MySQL Internal database network only

Direction is More Important Than Port Number

  • ONVIF discovery is initiated by the platform via multicast, followed by the platform calling back the device via SOAP/HTTP and RTSP.
  • GB28181 devices typically register actively, but after the platform requests a stream, the device must send media to the specified RTP address.
  • Web browsers access the API domain, which may not necessarily be the same as the media domain.
  • RTC requires both HTTPS signaling and ICE media; TURN relay requires its own port pool.
  • In multi-node deployments, the address and port of every MediaServer must be reachable from the end-user network.

RTP Modes

  • PerStream: Each stream uses an independent RTP port; rtp_proxy.port can be 0, and fixed port 10000 is not used.
  • Hybrid: Independent ports and shared ports coexist; the shared base port must be open.
  • FixedOnly: All streams use shared ports; the configured fixed port must be open.

The RTP range must be sufficient to accommodate peak concurrency and release latency, and must be consistent with the operating system, firewall, and container mappings.

HTTPS and Certificates

The typical public entry point is 443/TCP. HTTP-01 certificate requests also require 80/TCP; DNS-01 does not require port 80 to be open. Port 443 cannot replace RTSP, RTMP, SIP, RTP, or ICE media ports.

Principle of Least Privilege

Create rules based on source network segment, target service, protocol, and direction. The database, MediaServer API, and internal node interfaces must not be exposed to the public internet. After making changes, verify from the actual source network and perform packet captures; do not rely solely on the firewall console showing "Allowed" as evidence.