Skip to main content
All terms

STUN vs TURN

STUN helps a device discover its public address to enable a direct connection; TURN relays the traffic when a direct connection cannot be made.

STUN: discovering your public address

Session Traversal Utilities for NAT (STUN), specified in RFC 8489, is a lightweight request-and-response protocol. A device sends a binding request to a STUN server, and the answer reports the public address and port the request came from, known as the device's server-reflexive address. STUN helps two devices try a direct connection, but it never carries the session itself, so a STUN server needs very little bandwidth.

TURN: relaying when direct fails

Traversal Using Relays around NAT (TURN), specified in RFC 8656 as an extension of STUN, allocates an address on a relay server. Both sides send their traffic to the relay, which forwards it. TURN works when nothing else does, but every byte of the session crosses the relay, which adds latency and costs the operator bandwidth.

ICE: choosing between them

Interactive Connectivity Establishment (ICE), RFC 8445, ties the two together. Each side gathers candidates (local addresses, server-reflexive addresses from STUN and relayed addresses from TURN), exchanges them, tests pairs and keeps the best working one, preferring direct paths. WebRTC uses ICE, STUN and TURN in exactly this way.

How Vexaro Desk does it

Vexaro Desk does not use TURN. When a network rules out a direct connection, the session goes through Vexaro's own relays instead, and the client connects only to a relay it can authenticate.

Direct sessions are end-to-end encrypted. When a network forces a relayed connection, traffic stays encrypted in transit through Vexaro-operated relays.

STUN, TURN and ICE compared

STUN, TURN and ICE compared
STUNTURNICE
Standard1,2,3RFC 8489RFC 8656RFC 8445
Purpose1,2,3Discover the public address and portRelay traffic through a serverGather, test and choose candidate paths
Carries session traffic1,2,3NoYesNo, it picks the path
Server load1,2,3Small requests onlyThe whole session's bandwidthNone of its own; it uses STUN and TURN servers

Frequently asked questions

What does STUN do?
It tells a device the public address and port its traffic appears to come from, so two devices can try to connect directly. It does not carry session traffic.
What is TURN and when is it used?
TURN is a relay: both sides send traffic to a TURN server, which forwards it. It is used when a direct connection cannot be established, because it always works but costs latency and bandwidth.
Do I need both STUN and TURN?
For WebRTC-style connectivity, usually yes: STUN makes direct connections possible, TURN covers the cases where they fail, and ICE chooses between them. Products with their own relay, such as Vexaro Desk, use that relay instead of TURN.
Does Vexaro Desk use TURN?
No. Vexaro Desk connects directly wherever the network allows, and otherwise through Vexaro's own relays, which the client authenticates before it connects.

See it in Vexaro Desk

Vexaro Desk brings attended and unattended access, NAT traversal, an adaptive codec engine and governance together in one console. It is in early access, and you can create a free account to try it.