Overview
The Softstream Relay Network Model uses multiple components to establish and maintain a Softstream session between the Softstream Client and Softstream Server.
The primary components are:
- Signal Server: Runs in the Softdrive control plane and coordinates session setup.
- Relay Server(s): Run in the Softdrive environment and carry session traffic between the Softstream Client and the Softstream Server.
Both the Softstream Client and Softstream Server connect to the Signal Server during session establishment.
When a session starts, the Signal Server records the public IP address it observes for each side of the connection and provides this information to the Relay Server.
Applies To
- Softdrive Virtual Desktops
- Softstream Client
- Softstream Server
- Softstream Relay Network
- Zero Trust Network Access (ZTNA) solutions
- Secure Web Gateways
- SD-WAN environments
- Cloud firewalls
- Multiple NAT gateways or public internet egress paths
Why Consistent Public IPs Matter
A Softstream session uses several separate network flows to establish and maintain connectivity.
The Relay Server only accepts session traffic originating from the public IP addresses recorded during the signaling process.
If one of the Softstream network flows reaches the Relay Server from a different public IP address, the Relay Server rejects that traffic. Depending on which network flow is affected, the Softstream session may fail or behave intermittently.
For example, a device may initially communicate with the Signal Server through Public IP A, but subsequently send a Softstream connection to the Relay Server through Public IP B.
Because the Relay Server is expecting traffic from Public IP A, the connection originating from Public IP B is rejected.
This behavior can make connectivity problems appear intermittent because some network flows may use the expected public IP while others use a different egress path.
Common Causes
This condition can occur when traffic from a single device is allowed to leave the network through multiple public IP addresses or internet egress paths.
Common examples include:
- Zero Trust network clients such as Zscaler, Cato, or Netskope
- Secure Web Gateways
- SD-WAN solutions
- Cloud firewall services
- High Availability (HA) firewall pairs using multiple public IP addresses
- Multiple NAT gateways
- Any design where routing or flow hashing can send different connections through different egress paths
Requirement
Each side of the Softstream session must use a single, consistent public IP address for all of its Softstream traffic for the duration of the session.
- All traffic from the Softstream Client to the Signal Server and Relay Servers must leave through the same public IP address for the duration of the session.
- All traffic from the Softstream Server to the Signal Server and Relay Servers must leave through the same public IP address for the duration of the session.
Note: The Softstream Client and Softstream Server do not need to share the same public IP egress as each other.
For example, the following configuration is valid:
- Softstream Client → Public IP 203.0.113.10
- Softstream Server → Public IP 198.51.100.20
The important requirement is that each side independently maintains its respective public IP consistently throughout the Softstream session.
Recommended Network Configuration
Where needed, configure a bypass, direct internet route, static route, or other network policy so that Softstream traffic always uses a single public egress IP from both the client and server perspectives.
Zero Trust Systems
For environments using Zero Trust or Secure Web Gateway solutions:
- Exclude the Signal Server and Relay Server addresses from the Zero Trust tunnel so that this traffic goes directly to the internet rather than through the Zero Trust cloud, where appropriate.
- Ensure that 5-tuple-based network flows exit through the same consistent public IP.
- Confirm that consistent public IP egress applies to both UDP and TCP traffic.
Examples of environments where this configuration may need to be reviewed include Zscaler, Cato, Netskope, and other Zero Trust Network Access or Secure Web Gateway platforms.
Cloud Networks
For Softstream Servers or Softdrive Virtual Desktops hosted within a cloud or routed network environment:
- Statically route Signal Server and Relay Server traffic from the Softstream Server / Softdrive Virtual Desktop through a single NAT gateway.
- Avoid routing Softstream traffic across multiple NAT gateways when this could result in different public source IP addresses.
- If multiple egress paths are required for other network traffic, use routing or policy rules to keep Softstream traffic on a consistent path.
Expected Result
After the network configuration is properly applied:
- Softstream Client traffic uses a consistent public IP address.
- Softstream Server traffic uses a consistent public IP address.
- Signal Server and Relay Server connections observe the expected source IP addresses.
- Softstream session traffic is not rejected because of unexpected public IP changes.
- Intermittent session establishment or connectivity failures caused by multiple egress IPs are eliminated.
Troubleshooting
If users experience intermittent Softstream connectivity, session establishment failures, or unexpected disconnections, verify the public IP used by Softstream traffic.
Check whether:
- The device has multiple internet connections or egress paths.
- A Zero Trust client is routing some traffic through a cloud gateway while other traffic goes directly to the internet.
- Different TCP or UDP connections are leaving through different public IP addresses.
- SD-WAN is distributing connections across multiple WAN links.
- Multiple NAT gateways are being used.
- An HA firewall configuration can translate connections through different public IP addresses.
- Routing changes occur after the Softstream session has already been established.
If possible, temporarily configure the affected device or network to use a single internet egress path and test the Softstream session again.
If the issue no longer occurs when using a single public IP, review the existing routing, NAT, Zero Trust, firewall, or SD-WAN configuration to ensure Softstream traffic maintains consistent public IP egress.
Contact Softdrive Support
If the issue continues after confirming consistent public IP egress, contact Softdrive Support for further assistance.
When contacting Support, provide:
- Affected user
- Softdrive Virtual Desktop / computer name
- Approximate date and time of the issue
- Public IP observed from the client network
- Details about any Zero Trust, firewall, SD-WAN, VPN, or Secure Web Gateway solution in use
- Whether the issue occurs when testing from a different network or direct internet connection
SEO
Title: Softstream Relay Network - Consistent Public IP Requirements
Description: Learn why Softstream Relay Network sessions require consistent public IP egress and how to configure Zero Trust, SD-WAN, NAT gateways, cloud firewalls, and other network services to prevent intermittent Softdrive connectivity issues.