Configure a SonicWall Firewall

This guide explains how to configure a SonicWall firewall to allow Reemo to use an optimal connection (direct/udp) and avoid unnecessary fallback to relays.
A proper configuration reduces latency and improves the audio/video quality of sessions.
Without this configuration, Reemo can still work, but connections will fall back to relays (relay/tcp, relay/udp, websocket) with reduced performance.
Before you begin, make sure your SonicWall firewall (SonicWall NGFW, SonicOS 7.x or 8.x) is properly installed and accessible via its web administration interface.
Then log in to the interface with your administrator credentials.

Note

This configuration is provided as an example.
Screens may vary slightly depending on your SonicWall version (SonicOS).
The suggested object names (Reemo TURN, Reemo Services, etc.) are indicative: you may use your own conventions.

Step 1: Configure the TURN server

In Policies > Objects > Address Objects, add the following addresses:

Address Objects

Address Objects.

  • Reemo TURN:
    • Zone Assignment: WAN

    • Type: FQDN

    • FQDN Hostname: turn.cloudflare.com

Adding the TURN address

Adding the TURN address.

Next, add the required services:

  • Service UDP 3478 (TURN):
    • Protocol: UDP(17)

    • Port Range: 3478 - 3478

TURN UDP 3478 Service

TURN UDP 3478 Service.

  • Service UDP 58200 (TURN):
    • Protocol: UDP(17)

    • Port Range: 58200 - 58200

TURN UDP 58200 Service

TURN UDP 58200 Service.

  • Service TCP 3478 (TURN):
    • Protocol: TCP(6)

    • Port Range: 3478 - 3478

TURN TCP 3478 Service

TURN TCP 3478 Service.

Create a Service Group combining these three services.

TURN Service Group

TURN Service Group.

Finally, configure the rules:

  • Create an Access Rule to allow the TURN server with high priority:
    • Policy Name: Reemo TURN

    • Action: Allow

    • From: LAN

    • To: WAN

    • Source Port: Any

    • Service: Reemo TURN Services

    • Source: LAN Subnets

    • Destination: Reemo TURN

    • Users Included: All

TURN Access Rules

TURN Access Rules.

  • Add a NAT Policy for the TURN server:
    • Name: Reemo NAT TURN Servers

    • Original Source: LAN Subnets

    • Original Destination: Reemo TURN

    • Original Service: Reemo TURN Services

    • Enable NAT Policy: checked

    • Advanced > Disable Source Port Remap: checked

TURN NAT Policy

TURN NAT Policy.

Disable Source Port Remap option

Disable Source Port Remap option.

Note

The Disable Source Port Remap option is essential to preserve the original source port and ensure optimal compatibility with Reemo.

Step 2: Configure the Reemo service

Add a Service Object for the Reemo protocol:
  • Name: Reemo Services

  • Protocol: UDP(17)

  • Port Range: 58200 - 58400

Reemo Service Object

Reemo Service Object.

Then create an Access Rule:
  • Policy Name: Reemo Service

  • Action: Allow

  • From: LAN

  • To: WAN

  • Service: Reemo Services

  • Source: LAN Subnets

  • Destination: Any

  • Users Included: All

Reemo Access Rule

Reemo Access Rule.

Finally, create an associated NAT Policy, with high priority:
  • Name: Reemo Service NAT

  • Original Source: LAN Subnets

  • Original Destination: Any

  • Original Service: Reemo Services

  • Enable NAT Policy: checked

  • Advanced > Disable Source Port Remap: checked

Reemo NAT Policy

Reemo NAT Policy.

Disable Source Port Remap option

Disable Source Port Remap option.

Step 3: Extended UDP configuration for Reemo

Add a Service Object specifically for UDP:
  • Name: Reemo UDP

  • Protocol: UDP(17)

  • Port Range: 1024 - 65535

Reemo UDP Service

Reemo UDP Service.

Create an Access Rule:
  • Policy Name: Reemo UDP

  • Action: Allow

  • From: LAN

  • To: WAN

  • Source Port: Reemo Services (58200–58400)

  • Service: Reemo UDP (1024–65535)

  • Source: LAN Subnets

  • Destination: Any

  • Users Included: All

Reemo UDP Rule

Reemo UDP Rule.

Finally, create an associated NAT Policy:
  • Name: Reemo UDP NAT

  • Original Source: LAN Subnets

  • Original Destination: Any

  • Original Service: Reemo UDP

  • Enable NAT Policy: checked

  • Advanced > Disable Source Port Remap: checked

Reemo UDP NAT Policy

Reemo UDP NAT Policy.

Disable Source Port Remap option

Disable Source Port Remap option.

Configuration overview

Configured Rules:

Configured Rules Overview

Configured Rules Overview.

Configured NAT Policies:

Configured NAT Policies Overview

Configured NAT Policies Overview.

Summary: Ports and addresses to open

For quick reference, here is a summary table of the flows required for Reemo to work properly in direct/udp mode:

Usage

Protocol

Ports

Destination

Signal server

TCP/UDP

443

signal.reemo.io

TURN server

TCP/UDP

3478

turn.cloudflare.com

TURN server (fallback)

TCP/UDP

443

turn2.reemo.io

Reemo Protocol In

UDP

58200–58400

Browser (client device)

Reemo Protocol Out

UDP

1024–65535 (src 58200–58400)

Remote computer (Reemo Agent)