Commit Graph
5 Commits
Author SHA1 Message Date
outis1one 7d3bb42854 Merge pull request #1 from outis1one/claude/opnsense-turn-config-01KmxaPaGgfN7LemBpquwJnb
v1.24: Complete OPNsense/VLAN TURN configuration automation
2025-12-02 19:38:36 -05:00
Claude 9abc895970 v1.24: Add FQDN separation, IP type detection, and optional Google STUN
Major enhancements addressing user feedback:

1. **SEPARATE SIP AND TURN DOMAINS**
   - Added support for turn.example.com separate from sip.example.com
   - Updated Caddy cert sync to search for certs covering both domains
   - Supports wildcard certs (*.example.com) or multi-SAN certs
   - Caddy snippet generator now shows both domains when different
   - Config variables: DOMAIN_NAME (SIP) and TURN_DOMAIN (TURN)

2. **STATIC vs DYNAMIC IP DETECTION**
   - New check_ip_type_and_dns() function asks user about IP type
   - Detects static vs dynamic public IP configuration
   - For dynamic IPs, checks if user has DDNS configured
   - **STOPPING POINT** for users without DDNS:
     * Guides to popular DNS providers (Cloudflare, Namecheap, etc.)
     * Explains router built-in DDNS options
     * Lists dedicated DDNS services (No-IP, DynDNS)
   - **VPN ALTERNATIVE** strongly recommended:
     * Suggests Tailscale with installation instructions
     * Explains benefits: no port forwarding, no COTURN, no IP issues
     * More secure than exposing services
   - Called automatically during COTURN installation

3. **GOOGLE STUN MADE OPTIONAL**
   - No longer automatically falls back to Google STUN
   - Asks user during setup_internet_access()
   - New config: USE_GOOGLE_STUN (y/n)
   - rtp.conf generates three modes:
     * COTURN configured: uses local TURN server
     * Google STUN enabled: uses stun.l.google.com
     * Neither: direct connections only (for VPN setups)
   - Clearly explains pros/cons of each option

4. **ENHANCED CADDY CERT SYNC**
   - Searches for certs covering BOTH SIP and TURN domains
   - Validates cert coverage for each domain separately
   - Provides helpful hints if cert not found (wildcard or multi-SAN)
   - Handles same-domain scenario (TURN = SIP) efficiently
   - Displays which domains were covered in success message

5. **CONFIGURATION VARIABLES ADDED**
   - USE_GOOGLE_STUN: Enable/disable Google STUN fallback
   - IP_TYPE: "static" or "dynamic"
   - HAS_DYNAMIC_DNS: "y" or "n"
   - All saved to config file for persistence

ADDRESSES USER CONCERNS:
- "Do I need turn.example.com?" → Yes, supported now
- "What about dynamic IP?" → Guided through DDNS or VPN setup
- "Google as fallback optional?" → Yes, user chooses
- "VPN automation?" → Kept simple, just suggestions (too fragile)

All changes maintain full automation - no manual file editing required.
2025-12-02 23:54:52 +00:00
Claude 2096da31cc v1.24: Complete OPNsense/VLAN TURN configuration automation
Major improvements:

1. COMPREHENSIVE OPNsense/pfSense Guide
   - Complete network topology (LAN 192.168.1.0/24 + VLANs 20/30/40)
   - Step-by-step firewall rules for VLAN isolation
   - Detailed port forwarding tables (WAN → COTURN/Asterisk)
   - Visual flow diagrams for cross-VLAN communication
   - Testing procedures for TURN/COTURN validation
   - All rules properly ordered (Allow specific → Block general)

2. Enhanced COTURN Configuration
   - Auto-detects and binds to local IP (listening-ip/relay-ip)
   - Configured for OPNsense/VLAN environments
   - Added TLS support on port 5349
   - Proper relay port range (49152-65535)
   - Optimized for NAT traversal

3. Asterisk Auto-Configuration
   - Added ice_support=yes to all transports (UDP/TCP/TLS)
   - rtp.conf auto-configures with COTURN when enabled
   - Automatic TURN credentials injection
   - Falls back to Google STUN when COTURN not configured
   - No manual editing required

4. Baresip Auto-Configuration
   - Automatically injects TURN server configuration
   - Uses COTURN credentials when available
   - Zero manual configuration needed

AUTOMATION: All configurations now handle themselves automatically.
Nothing requires manual editing/configuration/starting by hand.

Fixes foggy instructions, replaces with crystal-clear OPNsense guide.
2025-12-02 23:33:57 +00:00
outis1one 64c5f9916f Add files via upload 2025-12-02 18:25:18 -05:00
outis1one 7cc57c4a00 Initial commit 2025-11-28 18:28:24 -05:00