If possible it's best to whitelist based on domain names. The following domains should have access:
*.letsgetdigital.io *.daily.co turn.aquila-eu.wbcnf.net
turn.aquila-eu.wbcnf.net is a specific server for Samba used in case certain ports are blocked.
The server tries to proxy media traffic over UDP or TCP on ports 80 or 443. If media traffic cannot be carried over the direct connection to those UDP ranges on the mediaserver - the front end tries each port / protocol to see if it can carry media traffic that way.
TURN is only used as a last resort, so it either allows the mediaserver UDP range OR allows UDP/443 (preferred) to the TURN server.
For more information see (select the 'Ports' tab):
Testing the TURN server
You can test in Windows by playing with the in built firewall.
Create a rule - Block UDP out - ports : 1000-65535 ( don't enable it )
Join a session and broadcast
Enable the rule - note your audio and video freezes
Refresh browser - note your audio and video works again
If you really want to prove TURN is being used to carry traffic, you can also inspect chrome://webrtc-internals/
Select the legacy API to get the stats from there, and find 'Conn-0-1-0) googCandicatePair' The find 'googleLocalCandidateType'
With the UDP outgoing ports blocked, this changes to relay meaning the TURN server is proxying the media traffic. Without these ports blocked - you will likely see stun or prflx candidate show there.
Default SSL connection
For signalling and media tunnelling, where necessary
40000 - 65534
For direct peer-to-peer media connections
Let's Get Digital can possibly use the following IP's.
IPv4 220.127.116.11/20 18.104.22.168/22 22.214.171.124/22 126.96.36.199/22 188.8.131.52/18 184.108.40.206/18 220.127.116.11/20 18.104.22.168/20 22.214.171.124/22 126.96.36.199/17 188.8.131.52/15 184.108.40.206/12 220.127.116.11/13 18.104.22.168/22
IPv 2400:cb00::/32 2606:4700::/32 2803:f800::/32 2405:b500::/32 2405:8100::/32 2a06:98c0::/29 2c0f:f248::/32
22.214.171.124/21 126.96.36.199/22 188.8.131.52/25 184.108.40.206/27 220.127.116.11/27 18.104.22.168/27 22.214.171.124/27 126.96.36.199/27 188.8.131.52/27 184.108.40.206/29 220.127.116.11/26 18.104.22.168/30 22.214.171.124/29 126.96.36.199/29 188.8.131.52/29 184.108.40.206/29 220.127.116.11/29
18.104.22.168 22.214.171.124 126.96.36.199 188.8.131.52 184.108.40.206 220.127.116.11 18.104.22.168 22.214.171.124 126.96.36.199 188.8.131.52 184.108.40.206 220.127.116.11 18.104.22.168 22.214.171.124 126.96.36.199 188.8.131.52 184.108.40.206