STUN Server Functionality Explained
Learn how STUN (Session Traversal Utilities for NAT) servers help peers discover their public IP addresses and port mappings.
STUN Server Functionality Explained is a free Real-Time Streaming Systems (WebRTC + Live Data) lesson on CoddyKit — lesson 2 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Real-Time Streaming Systems (WebRTC + Live Data) learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.
What is a STUN Server?
Welcome! Today we'll unravel the mystery of STUN servers. STUN stands for Session Traversal Utilities for NAT. It's a key technology that helps WebRTC connections work.
Its main job is to help devices behind a NAT (Network Address Translator) discover their public IP address and port number. This is crucial for establishing direct peer-to-peer connections.
NAT: A Quick Reminder
Remember NAT from our previous lesson? NAT helps multiple devices in a private network share a single public IP address. While great for conserving IPs, it hides your device's true network address from the outside world.
For WebRTC, this is a problem! Peers need to know each other's actual, routable addresses to connect directly. STUN is here to solve this.
STUN's Core Function: Discovery
Think of a STUN server as a friendly helper on the public internet. When your device wants to know its public identity, it asks the STUN server, "Hey, what's my public IP and port from your perspective?"
The STUN server replies with the public address it observed your request coming from. This is your device's public 'face' to the internet.
The STUN Request Flow
Here's how a STUN request typically works:
- Your WebRTC client sends a 'binding request' to a known STUN server.
- This request travels through your local network and then through your NAT.
- The NAT modifies the packet, assigning a public IP and port before sending it out.
- The STUN server receives this request.
Understanding the STUN Response
When the STUN server gets your request, it records the source IP and port of the incoming packet. This is what it sees as your public address.
It then sends a 'binding response' back to your client, containing this observed public IP and port. Your client now knows how it appears to the outside world!
Binding Requests in Detail
The 'binding request' isn't just a simple 'hello'. It's a specific message format defined by the STUN protocol.
- It contains a transaction ID to match requests with responses.
- It asks the server to reflect the client's observed network address.
- The response carries attributes like
XOR-MAPPED-ADDRESS, which is the public IP and port.
STUN & WebRTC's ICE
STUN servers are a fundamental part of WebRTC's ICE (Interactive Connectivity Establishment) framework.
ICE uses STUN (and sometimes TURN) to gather all possible network addresses (called 'candidates') for a peer. These candidates include local IPs, public IPs (from STUN), and relayed IPs (from TURN).
Configuring STUN in WebRTC
In WebRTC, you configure STUN servers as part of your RTCPeerConnection setup. The browser then handles the communication with the STUN server automatically to gather ICE candidates.
Here's how you define a STUN server for your peer connection:
const configuration = {
iceServers: [
{
urls: 'stun:stun.l.google.com:19302'
}
]
};
const peerConnection = new RTCPeerConnection(configuration);
// The browser will now use the STUN server
// to discover public IP/port for ICE candidates.STUN vs. NAT Types
STUN works very well with certain types of NATs, like Full Cone NAT and Restricted Cone NAT, where the mapping of internal to external ports is consistent.
However, STUN can struggle with more complex NATs, such as Symmetric NATs. For these, a TURN server (which we'll cover next!) is often required to relay traffic.
Test Your STUN Knowledge
Which of the following best describes the primary role of a STUN server in WebRTC?
STUN: Your NAT Helper
Great job! You've learned that STUN (Session Traversal Utilities for NAT) servers are vital for WebRTC.
- They help devices behind NATs find their public IP and port.
- This discovery is crucial for ICE to gather connectivity candidates.
- STUN works well for many NAT types, but not all.
Next, we'll explore TURN servers, which tackle the toughest NAT challenges!
Frequently asked questions
Is the “STUN Server Functionality Explained” lesson free?
Yes — the full text of “STUN Server Functionality Explained” is free to read here on the web, and the Real-Time Streaming Systems (WebRTC + Live Data) course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Real-Time Streaming Systems (WebRTC + Live Data) course, upgrade to CoddyKit PRO.
What will I learn in “STUN Server Functionality Explained”?
Learn how STUN (Session Traversal Utilities for NAT) servers help peers discover their public IP addresses and port mappings. You practise Real-Time Streaming Systems (WebRTC + Live Data) with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.
Do I need any experience to start Real-Time Streaming Systems (WebRTC + Live Data)?
No prior experience is required. Real-Time Streaming Systems (WebRTC + Live Data) on CoddyKit is structured for beginners through advanced learners; this is — lesson 2 of 4, so you can start here or from the beginning and move at your own pace.
How long does the “STUN Server Functionality Explained” lesson take?
Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.
Can I write and run code in this Real-Time Streaming Systems (WebRTC + Live Data) lesson?
Yes. Every Real-Time Streaming Systems (WebRTC + Live Data) lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.
All lessons in this course
- NAT and Firewall Challenges
- STUN Server Functionality Explained
- TURN Server for Relayed Connections
- Deploying and Securing Your Own TURN Server