Cant get Hik-Connect "Online" through company firewall.

Noziroh

n3wb
Joined
Dec 25, 2015
Messages
16
Reaction score
2
Location
Denmark
Hi guys

I have a Hikvision DS-96128NI-I16C NVR that im trying to get to go in "Online" status with Hik-Connect.
It is running on a Cisco based company network with a ASA firewall.
It has the lastest firmware V4.40.506 build 201218.
At the moment I have forwarded three ports from our external/public IP to its internal IP, allowing communication both ways:
HTTP 80 TCP
Server Port 8000 TCP
RTSP 554 TCP

I am able to connect to it from our external/public IP, login, watch live stream and recordings. So, so far so good.
But this does not seem to be enough for Hik-Connect status to become "Online".
(Hik-Connect "Activated" box is ticked)

I have tried several different Server-Adresses:
dev.hik-connect.com
litedev.hik-connect.com
dev.eu.hik-connect.com
litedev.eu.hik-connect.com
Even what I have been told should be dev.hik-connect.com's IP: 99.80.155.28
(We are located in EU)
Restart after each - No luck.

The NVR's internal setup is as following:
IPv4 Adresse: 10.10.9.127
IPv4 Subnet: 255.255.254.0
IPv4 Gateway: 10.10.8.1
DNS: 8.8.8.8
Alternate DNS: 8.8.4.4

I dident do the original setup of the system, so I cant tell why they choose that subnet and gateway instead of 255.255.255.0 and 10.10.9.1.

I have tried a few other DNS's with restarts, without any luck.

So I tried contacting Hikvisions Tech Support.
They told me to open the following ports:
Ports:Module:
6002(UDP/TCP)STUN
6600VTDU
6800(UDP/TCP)DAS
6900(SSL)DAS
7100VTDT
7200Alarm
7300Playback
7400Alarm
7900Playback
8089Stream
8555LBS
8666LBS2.0
9554Playback
9664TTS
32723Stream
12001:14000VTDU/Playback/TTS

To me this looks like a massiv amount of ports required for Hik-Connect.
I have not applied any of these ports to our firewall yet.
I have read a few places about ports 9010 and 9020, but since they are not even mentioned in the list from Hikvisions Tech Support, I havent tried them.
Can anyone confirm that all these ports are indeed required to reach "Online" status for Hik-Connect?

I did alooot of Googleing on this, and most seem only to mention the three ports: 80, 8000 and 554.
I was not able to find much in here from the search function either, but maybe my search skills are crap.

What am I missing, what has been setup wrong?
Everything else works fine.
We have around 80 cameras connected to the NVR, all recording and viewing fine.

Any and all help is appreciated :)
 

alastairstevenson

Staff member
Joined
Oct 28, 2014
Messages
15,950
Reaction score
6,786
Location
Scotland
At the moment I have forwarded three ports from our external/public IP to its internal IP, allowing communication both ways:
HTTP 80 TCP
Server Port 8000 TCP
RTSP 554 TCP
This is intended to be constructive criticism.

By creating this crude and insecure ability for the entire internet to access a potentially vulnerable device that's not been designed or certified to be cyber secure, you may well be opening up your company's data and assets to significant risk.
Have you discussed this with your management, and have they understood the risks and agreed a risk assessment?

I'd strongly suggest that you research how to implement remote access solutions that are designed to be cyber secure, such as current-generation VPNs.
There are plenty of how-tos and discussion on that topic on this forum.
The forum search facility will yield lots of info.
 

4l3j4ndr0

n3wb
Joined
Nov 30, 2021
Messages
1
Reaction score
0
Location
Venezuela
Hi,

I have the same problem with my NVR, It is a DS-96128NI-I16 model. I have done a lot of things but it doesn't go online. I called to Hikvision support and they insist the problem is my network configuration but It isn't, my 128 IP cameras are configured with Hik-connect and all of them are Online, so definitely is not the network configuration. Did you already find any solution?

Thanks in advance.
 

user8963

Known around here
Joined
Nov 26, 2018
Messages
1,465
Reaction score
2,315
Location
Christmas Island
Hi,

I have the same problem with my NVR, It is a DS-96128NI-I16 model. I have done a lot of things but it doesn't go online. I called to Hikvision support and they insist the problem is my network configuration but It isn't, my 128 IP cameras are configured with Hik-connect and all of them are Online, so definitely is not the network configuration. Did you already find any solution?

Thanks in advance.
no one should use hikconnect cloud for ip cameras... the only devices are their alarm system and doorbell , because they sadly need cloud connection to work.

but stupid people never die

if you use a proper firewall just put the nvr into a vlan without any rules. you will see in the logs which servers are called. you can also use wireshark
 
Top