Gestion des adresses IP WebRTC par URL
Vérifié avec Google Chrome — mis à jour le 2 septembre 2026
Pris en charge sur : Microsoft Windows 7 ou version ultérieure
Chemin dans la console GPO
Configuration ordinateur\Modèles d'administration\Google\Google Chrome\Paramètres WebRTC Configuration utilisateur\Modèles d'administration\Google\Google Chrome\Paramètres WebRTC Description
Cette règle permet de limiter les adresses IP et interfaces utilisées par WebRTC pour essayer d'identifier la meilleure connexion disponible pour chaque format d'URL spécifique. Elle accepte une liste de paires de formats d'URL et de types de gestion. Les formats d'URL sont vérifiés dans l'ordre. Le premier qui correspond détermine quelle gestion est utilisée par WebRTC pour le domaine. Lorsque l'URL du document actuel ne correspond à aucune entrée, elle utilise la configuration définie par la règle WebRtcIPHandling. Pour en savoir plus sur les formats d'entrée valides, veuillez consulter https://chromeenterprise.google/policies/url-patterns/. Les caractères génériques (*) sont autorisés. Cette règle ne tient compte que de l'origine. Ainsi, tout chemin d'accès dans le format d'URL est ignoré. Valeurs de gestion valides : * default : WebRTC utilise toutes les interfaces réseau. * default_public_and_private_interfaces : WebRTC utilise toutes les interfaces publiques et privées. * default_public_interface_only : WebRTC utilise toutes les interfaces publiques, mais pas les interfaces privées. * disable_non_proxied_udp : WebRTC utilise le proxy UDP SOCKS ou bascule sur le proxy TCP. Consultez la section 5.2 du document RFC 8828 (https://tools.ietf.org/html/rfc8828.html#section-5.2) pour obtenir une description détaillée de toutes les valeurs de gestion. Consultez la page https://chromeenterprise.google/policies/?policy=WebRtcIPHandlingUrl pour en savoir plus sur le schéma et le formatage. Exemple de valeur : [ { "url": "https://www.example.com", "handling": "default_public_and_private_interfaces" }, { "url": "https://[*.]example.edu", "handling": "default_public_interface_only" }, { "url": "*", "handling": "disable_non_proxied_udp" } ]
Registre
Software\Policies\Google\Chrome Software\Policies\Google\Chrome Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Appliquer les deux portées crée une configuration ambiguë (la portée ordinateur prévaut sur la portée utilisateur). Ne le faites que volontairement.
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Gestion des adresses IP WebRTC par URL
; State: Enabled
; Scope: Computer (HKLM)
; Supported on: Microsoft Windows 7 ou version ultérieure
[HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome]
"WebRtcIPHandlingUrl"="" Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Gestion des adresses IP WebRTC par URL
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Windows 7 ou version ultérieure
$path = 'HKLM:\Software\Policies\Google\Chrome'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'WebRtcIPHandlingUrl' -Value '' -Type String Intune XML
Aucune correspondance directe Policy CSP / OMA-URI pour cette stratégie. Utilisez l'onglet Intune Remediation, ou importez l'ADMX dans Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Gestion des adresses IP WebRTC par URL
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Windows 7 ou version ultérieure
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Google\Chrome' -Name 'WebRtcIPHandlingUrl' -Expected '' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Gestion des adresses IP WebRTC par URL
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Windows 7 ou version ultérieure
$path = 'HKLM:\Software\Policies\Google\Chrome'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'WebRtcIPHandlingUrl' -Value '' -Type String Scripts SCCM
# Exported from gporais.com
# Policy: Gestion des adresses IP WebRTC par URL
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Windows 7 ou version ultérieure
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Gestion des adresses IP WebRTC par URL
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Windows 7 ou version ultérieure
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Google\Chrome' -Name 'WebRtcIPHandlingUrl' -Expected '' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Gestion des adresses IP WebRTC par URL
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Windows 7 ou version ultérieure
$path = 'HKLM:\Software\Policies\Google\Chrome'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'WebRtcIPHandlingUrl' -Value '' -Type String Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).