# Protecting WebRTC Server IP from Attacks

**URL:** <https://janus.discourse.group/t/protecting-webrtc-server-ip-from-attacks/1582>\
**Category:** Off Topic\
**Created:** [March 30, 2025, 7:59am UTC](https://janus.discourse.group/t/protecting-webrtc-server-ip-from-attacks/1582 "2025-03-30T07:59:50Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![LazyPanda](https://avatars.discourse-cdn.com/v4/letter/l/ad7895/32.png) [@LazyPanda](https://janus.discourse.group/u/LazyPanda)\
**Post date:** [March 30, 2025, 7:59am UTC](https://janus.discourse.group/t/protecting-webrtc-server-ip-from-attacks/1582/1 "2025-03-30T07:59:50Z")

</div>

I’m facing a security issue with WebRTC connections. By design, browsers expose the server’s IP address as ICE candidates during connection establishment. While it’s possible to hide the API layer using services like Cloudflare, we can’t hide the server’s IP address, which makes us vulnerable to attacks.

What approaches can I take to protect my WebRTC server? I’m considering placing my server behind a Cloudflare TURN server, but I’m not sure if this is a viable solution. How would I configure this in Janus Media Server?

Has anyone implemented a solution that successfully hides the WebRTC server IP while maintaining service functionality?

---

<div class="post-metadata">

**Author:** ![lorenzo](https://yyz2.discourse-cdn.com/free1/user_avatar/janus.discourse.group/lorenzo/32/425_2.png) [@lorenzo](https://janus.discourse.group/u/lorenzo)\
**Post date:** [April 3, 2025, 8:33am UTC](https://janus.discourse.group/t/protecting-webrtc-server-ip-from-attacks/1582/2 "2025-04-03T08:33:01Z")

</div>

I think that’s what Slack was doing back when they were using Janus:

> **[Is Slack's WebRTC Really Slacking? (Yoshimasa Iwase) - webrtcHacks](https://webrtchacks.com/slack-webrtc-slacking/)**
>
> Yoshimasa Iwase takes a deep look at Slack's WebRTC implementation to find it terminates all calls on its own TURN and uses a SFU for multi-party calling,
