Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    webrtc

    Scheduled Pinned Locked Moved NAT
    17 Posts 3 Posters 2.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • MikeV7896M
      MikeV7896
      last edited by

      Maybe the outbound NAT needs to be static for the device, so that the port is the same between the host and pfSense doing the NAT? Maybe there's something in the data that says what port the device is using, but the NAT on pfSense is using a different port on its connection, causing problems.

      The S in IOT stands for Security

      DaddyGoD J 2 Replies Last reply Reply Quote 0
      • DaddyGoD
        DaddyGo @MikeV7896
        last edited by DaddyGo

        @virgiliomi said in webrtc:

        Maybe the outbound NAT needs to be static

        you are on a very good way, but it is VMS system...
        something like that:
        https://en.wikipedia.org/wiki/Video_management_system

        or
        https://us.hikvision.com/en/partners/technology-partners/vms

        I hope this is the case, as this has not been explained properly by the OP 😉

        so like a game console, but not so complicated... hihiihi
        so it can be dangerous to misconfigure behind a firewall

        Cats bury it so they can't see it!
        (You know what I mean if you have a cat)

        1 Reply Last reply Reply Quote 0
        • J
          jacquesh @MikeV7896
          last edited by

          @virgiliomi can you give me an example how to configure this?

          DaddyGoD 1 Reply Last reply Reply Quote 0
          • MikeV7896M
            MikeV7896
            last edited by

            Re-reading everything now, outbound NAT isn't likely the issue. Since the VMS server probably isn't making an outbound connection to your device when you want to watch a camera, that was a poor suggestion.

            The S in IOT stands for Security

            1 Reply Last reply Reply Quote 0
            • DaddyGoD
              DaddyGo @jacquesh
              last edited by

              @jacquesh said in webrtc:

              can you give me an example how to configure this?

              if your VMS knows UPnP, and what I've seen so far is known...
              that will be the solution, but be careful this is dangerous on NGFW...

              separate the VMS network with a separate interface

              BTW:
              pls. note that pfSense does not block anything (just because it is), especially not RTSP stuff, ergo your settings are bad

              Cats bury it so they can't see it!
              (You know what I mean if you have a cat)

              J 1 Reply Last reply Reply Quote 0
              • J
                jacquesh @DaddyGo
                last edited by

                @daddygo when i enable upnp. it is still not working.
                when i swapp pfsense for en simple router it is working fine...

                DaddyGoD 1 Reply Last reply Reply Quote 0
                • DaddyGoD
                  DaddyGo @jacquesh
                  last edited by

                  @jacquesh said in webrtc:

                  when i swapp pfsense for en simple router it is working fine...

                  Ok

                  Now I'm interested in the thing better, send me a description of this VMS...

                  Cats bury it so they can't see it!
                  (You know what I mean if you have a cat)

                  J 1 Reply Last reply Reply Quote 0
                  • J
                    jacquesh @DaddyGo
                    last edited by

                    @daddygo is a local dutch solution: https://ensura.com/

                    J DaddyGoD 2 Replies Last reply Reply Quote 0
                    • J
                      jacquesh @jacquesh
                      last edited by

                      @jacquesh the strange thing is: when i install vmscore on a local server in my network, my client pc's in the local network has the same problem.

                      DaddyGoD 1 Reply Last reply Reply Quote 0
                      • DaddyGoD
                        DaddyGo @jacquesh
                        last edited by

                        @jacquesh said in webrtc:

                        is a local dutch solution:

                        okay I will read through it, well if I see anything....

                        Cats bury it so they can't see it!
                        (You know what I mean if you have a cat)

                        1 Reply Last reply Reply Quote 0
                        • DaddyGoD
                          DaddyGo @jacquesh
                          last edited by

                          @jacquesh said in webrtc:

                          when i install vmscore on a local server in my network,

                          I googled my brain to ruins and there is almost no description from this VMS ...
                          do you have some user or installation guides in your hand or PRTSC setup?

                          something like these:

                          78761b1b-d83b-4d45-9f32-c1e7f2fef21b-image.png

                          8f79be9e-545c-45a9-86fb-eb44355216d6-image.png

                          BTW:
                          This is a Hikvision VMS, running behind a pfSense....
                          I only threw ports up to 50K effortlessly,.... it works flawlessly, so your "vmscore" works differently

                          Cats bury it so they can't see it!
                          (You know what I mean if you have a cat)

                          J 1 Reply Last reply Reply Quote 0
                          • J
                            jacquesh @DaddyGo
                            last edited by

                            @daddygo
                            they say:"
                            VMSCORE Servers need to be behind a compatible NAT type (basically, anything but Symmetric NAT) in order for bidirectional communication to be possible through a firewall.

                            See here:
                            https://doc-kurento.readthedocs.io/en/stable/knowledge/nat.html#port-restricted-cone-nat

                            DaddyGoD 1 Reply Last reply Reply Quote 0
                            • DaddyGoD
                              DaddyGo @jacquesh
                              last edited by

                              @jacquesh said in webrtc:

                              basically, anything but Symmetric NAT

                              I found this yet, pls. read Jimp's response (second answer) about symmetric NAT, so you're not in a good position,....

                              https://forum.netgate.com/topic/57370/symmetric-nat

                              -a correct description of the VMS is required to assign static ports (I would ask this from the vms developers)
                              -or as I suggested 1: 1NAT

                              Cats bury it so they can't see it!
                              (You know what I mean if you have a cat)

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.