Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

live camera is not working on External ip to internal ip

Hi, We are facing problem in Live cam. Live cams have installed in Machine(good configration) when we are using live cams throug network it' s working fine but when we connect throught firwall (extneral ip to internal ip) it' s not working. But when i direct connect internet without firwall on machine and configure live ip . It' s working fine. Please help me. Thanks & Regards,
6 REPLIES 6
jasonb_FTNT
Staff
Staff

You need to find out what protocol and ports you need to open for this camera. Then you will need to create VIPs to access the camera from the outside.
Not applicable

I have a similar problem with a client' s camera system that is accessed via web browser over port 80. Disabling AV scanning for HTTP fixes this issue for us.
Not applicable

i' ve the same problem with CCTV, if i accessed it from internal network (LAN), it can works but if i accessed it from internet (i' ve used VIP), it didn' t work although i do not add a protection profile on this CCTV policy. Does anyone has used CCTV that can be accessed from internet? BTW....if i connected it directly to internet without FG, it' s working fine.
abelio

Jasonb' s above post shows you the way; you need identify exactly which ports actually use your device. Establish a session from the internet, with a sniffer you can see traffic and ips and ports involved; i.e: diagnose sniffer packet any " host <internal_camera_ip> and host <your internet test ip>" 2 After that, you can set the appropiate ports and services in your VIP.

regards




/ Abel

regards / Abel
Not applicable

I' ve already use VIP that map internal IP to external IP and set the service ANY, but it' s still don' t work. I can access the HTTP (the access of CCTV use a browser) but when i entered the username and password, it showed up pop up message that said " connection timeout" . But when i accessed it from the LAN, no problem occured. Maybe it worked for some of CCTV but not for all although i' ve been set the service " ANY" .
Not applicable

abelio and jasonb: Our 1000A is in transparent mode, and all IP addresses both inside and outside are public IP. No NAT or any other type of firewall is involved here. It seems that AV scanning on port 80 will drop traffic that streams (audio from internet radio in some cases) or isn' t pure HTTP. I' ve also seen where increasing the comfort client buffer size will allow higher bitrate audio streams to work properly. I have to run my interval at 1 second, and my buffer size to 8192.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors