# prefer direct connection over configured relay

**URL:** https://forum.syncthing.net/t/prefer-direct-connection-over-configured-relay/12777
**Category:** Support
**Created:** [January 27, 2019, 11:55am UTC](https://forum.syncthing.net/t/prefer-direct-connection-over-configured-relay/12777 "2019-01-27T11:55:24Z")
**Posts on this page:** 10
**Page:** 1

<div class="post-metadata">

### Author: ![octomike](https://forum.syncthing.net/letter_avatar_proxy/v4/letter/o/7ea924/32.png) [@octomike](https://forum.syncthing.net/u/octomike)
#### Post date: [January 27, 2019, 11:55am UTC](https://forum.syncthing.net/t/prefer-direct-connection-over-configured-relay/12777/1 "2019-01-27T11:55:24Z")

</div>

Oh hi !

I’ve seen topics on this before but haven’t found a complete answer yet…

We run a (public, FreeBSD) relay server in our organization’s network and configured our firewalled clients to use it with `relay://....`. Everything seems to work fine but what I don’t understand is why two firewalled clients always use the detour through the relay when in fact they could connect directly to each other.

We used pf to set a somewhat sane bandwidth limit for internal and external traffic on top of the unlimited strelay setting but this seems very unnecessary to me. It’d be much faster and simpler for our clients to not go through the relay at all and only use it to connect to external firewalled clients.

Any help? Is this behavior intended?

Cheers and thanks so much for this great piece of software

---

<div class="post-metadata">

### Author: ![AudriusButkevicius](https://forum.syncthing.net/user_avatar/forum.syncthing.net/audriusbutkevicius/32/277_2.png) [@AudriusButkevicius](https://forum.syncthing.net/u/AudriusButkevicius)
#### Post date: [January 27, 2019, 12:06pm UTC](https://forum.syncthing.net/t/prefer-direct-connection-over-configured-relay/12777/2 "2019-01-27T12:06:00Z")

</div>

What’s the end goal of what you want to achieve? You should give a more detailed description of what configuration changes you’ve made.

If you told clients to connect via relay:// addresses they will only connect via relays. If you told syncthing only listen on a relay:// it will only listen on relays, means others will only be able connect via relays.

Also, have you verified that your firewall rules actually work the way you expect using netcat or something?

---

<div class="post-metadata">

### Author: ![octomike](https://forum.syncthing.net/letter_avatar_proxy/v4/letter/o/7ea924/32.png) [@octomike](https://forum.syncthing.net/u/octomike)
#### Post date: [January 27, 2019, 12:21pm UTC](https://forum.syncthing.net/t/prefer-direct-connection-over-configured-relay/12777/3 "2019-01-27T12:21:38Z")

</div>

Hi Audrius! Okay I’ll try to explain better 🙂

The end goal is to save while also offer (a little) bandwidth:

- all our clients (external and internal) should directly connect to os (our relay) and not hog other relays
- still, our relay should be public to help out
- our relay should not use unlimited bandwidth though
- we configure all clients’ **Sync Protocol Listen Addresses** to use our relay with `relay://<IP>:443/?id=<KEY>`
- **but** our local clients should still be able to use their 1/10 GigE connections by connecting directly to each other if possible

And right now it looks like as if all clients always connect to each other via relay (the address is `relay-client`). Your remarks suggests that I can tell clients to listen on relays **and** their local interface? I think that would solve my problem. How do I do that?

---

<div class="post-metadata">

### Author: ![AudriusButkevicius](https://forum.syncthing.net/user_avatar/forum.syncthing.net/audriusbutkevicius/32/277_2.png) [@AudriusButkevicius](https://forum.syncthing.net/u/AudriusButkevicius)
#### Post date: [January 27, 2019, 12:39pm UTC](https://forum.syncthing.net/t/prefer-direct-connection-over-configured-relay/12777/4 "2019-01-27T12:39:52Z")

</div>

> [@octomike](#):
>
> **but** our local clients should still be able to use their 1/10 GigE connections by connecting directly to each other if possible

No, because all clients are listening on the relay and relay only, because you removed `default` where default translats to `tcp://0.0.0.0:22000 dynamic+relay://relays.syncthing.net/endpoint`.

You probably want `tcp://0.0.0.0:22000 relay://yourrelay`

---

<div class="post-metadata">

### Author: ![octomike](https://forum.syncthing.net/letter_avatar_proxy/v4/letter/o/7ea924/32.png) [@octomike](https://forum.syncthing.net/u/octomike)
#### Post date: [January 27, 2019, 12:46pm UTC](https://forum.syncthing.net/t/prefer-direct-connection-over-configured-relay/12777/5 "2019-01-27T12:46:15Z")

</div>

That makes total sense 🙂

I’ll experiment a little with `default relay://` and `tcp:// relay://` to see if everything checks out. Thank you so much.

---

<div class="post-metadata">

### Author: ![AudriusButkevicius](https://forum.syncthing.net/user_avatar/forum.syncthing.net/audriusbutkevicius/32/277_2.png) [@AudriusButkevicius](https://forum.syncthing.net/u/AudriusButkevicius)
#### Post date: [January 27, 2019, 12:59pm UTC](https://forum.syncthing.net/t/prefer-direct-connection-over-configured-relay/12777/6 "2019-01-27T12:59:56Z")

</div>

default + relay will result in connecting to two relays plus listen locally

---

<div class="post-metadata">

### Author: ![octomike](https://forum.syncthing.net/letter_avatar_proxy/v4/letter/o/7ea924/32.png) [@octomike](https://forum.syncthing.net/u/octomike)
#### Post date: [January 27, 2019, 1:01pm UTC](https://forum.syncthing.net/t/prefer-direct-connection-over-configured-relay/12777/7 "2019-01-27T13:01:38Z")

</div>

And then it’s round robin with these two relays? I’m a little reluctant to use hard coded ports in the default setting to be honest.

---

<div class="post-metadata">

### Author: ![AudriusButkevicius](https://forum.syncthing.net/user_avatar/forum.syncthing.net/audriusbutkevicius/32/277_2.png) [@AudriusButkevicius](https://forum.syncthing.net/u/AudriusButkevicius)
#### Post date: [January 27, 2019, 1:02pm UTC](https://forum.syncthing.net/t/prefer-direct-connection-over-configured-relay/12777/8 "2019-01-27T13:02:28Z")

</div>

I think the order of which relay will be used is undefined, probably the one it can connect to faster.

---

<div class="post-metadata">

### Author: ![Nummer378](https://forum.syncthing.net/user_avatar/forum.syncthing.net/nummer378/32/5958_2.png) [@Nummer378](https://forum.syncthing.net/u/Nummer378)
#### Post date: [January 27, 2019, 1:35pm UTC](https://forum.syncthing.net/t/prefer-direct-connection-over-configured-relay/12777/9 "2019-01-27T13:35:32Z")

</div>

My own configuration is this: relay://\<my\_relay\>, tcp://:22000. This is basically the same thing as the default config, just with a fixed relay instead of a “random” one.

This configuration enables direct connections over internet and relay connections. If local discovery is enabled, local connections are also possible. Syncthing will always prefer the direct connections, sometimes it connects first over relay and half a second later the log reads something like “replaced connection X with Y” when it switches to a direct connection instead of the relay.

tcp://:22000 makes Syncthing listen on both IPv4 and IPv6 on port 22000. From my knowledge, this is effectively the default behavior, syncthing will by default always bind to 22000 for the server-socket. If you want to randomize this, try if port 0 works.

PS: If you haven’t already, have a look at this: [https://docs.syncthing.net/users/config.html#listen-addresses](https://docs.syncthing.net/users/config.html#listen-addresses)

---

<div class="post-metadata">

### Author: ![system](https://forum-uploads.syncthingcdn.net/original/2X/0/0b50e0a202b22ae6a67190759e8c868805b8ed9f.png) [@system](https://forum.syncthing.net/u/system)
#### Post date: [February 26, 2019, 1:49pm UTC](https://forum.syncthing.net/t/prefer-direct-connection-over-configured-relay/12777/10 "2019-02-26T13:49:22Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
