Configure access to WebRTC-based destinations
You can configure
BlackBerry Access for macOS
and BlackBerry Access for Windows
to allow communication using WebRTC protocol-based web clients such as Citrix
VDI browser-based access.BlackBerry Access blocks the camera and microphone. Any WebRTC clients trying to use the camera or microphone on
Windows
or macOS
is not supported.WebRTC traffic can often have high bandwidth demands. For this reason,
BlackBerry
recommends routing this traffic directly. Route WebRTC traffic directly
If the WebRTC destination is accessible directly over the internet, use the following routing configuration:
- On theSecuritytab of theBlackBerry Accessapp configuration policy, clear theEnforce Strict Tunnelcheckbox to disable strict tunnel.
- Configure theBlackBerry DynamicsConnectivity profile to route traffic directly to the WebRTC destination, as follows:
- ForBlackBerry UEMversion 12.11 and later: Add the WebRTC destination URL to theAdditional serverssection and specifyDirect connectivity. This allows the connection to route directly even if the default route is set to use aBlackBerry Proxycluster.
- ForBlackBerry UEMversion 12.10 and earlier andGood Control: DisableRoute All. Ensure that existing internal domains or servers are configured to route throughBlackBerry Proxyclusters. Do not add the WebRTC destination to theBlackBerry DynamicsConnectivity profile. This will allow the connection to route directly.
- This configuration supports both TCP- and UDP-based WebRTC connections.TheBlackBerry DynamicsConnectivity profile and strict tunnel configuration have no effect on UDP connections. UDP connections route directly to the WebRTC destination through the local internet connection.
Route WebRTC traffic through BlackBerry Proxy
If the WebRTC destination is not directly accessible over the internet, or the traffic is required to route through a
BlackBerry Proxy
cluster, take the following items into consideration:- To route WebRTC traffic throughBlackBerry Proxyclusters, theBlackBerry Proxyclusters must be configured to use Direct Connect. For more information, see the Direct Connect content.If you do not configure theBlackBerry Proxyclusters with Direct Connect, the WebRTC destination does not load. For more information, visit support.blackberry.com/community to read article 62766.
- Ensure that enoughBlackBerry Proxyservers are installed to handle the load generated by the WebRTC traffic.
- This configuration supports only TCP-based WebRTC connections.BlackBerry Proxyservers support only TCP protocol. UDP-based WebRTC connections do not work if the traffic is routed throughBlackBerry Proxy.