[SOLVED] Cannot access Hikvision NVR using VPN (all other LAN devices fine)

sh500

n3wb
Joined
Feb 11, 2018
Messages
10
Reaction score
4
Hi all,

I recently setup OpenVPN server on my OpenWRT (LEDE) router. I am able to connect remotely and access other devices on my LAN, including the router itself and a NAS device. But for some reason I cannot access the Hikvision NVR (accessing it locally works fine of course). I cannot access the web configuration or using an app such as iVMS4500.

My LAN is on a 10.X.X.X network and the OpenVPN clients get assigned 192.168.200.X.

As I am able to access other devices on the same LAN as the Hikvision, is there anything else that I need to do on my router/Hikvision to get access?

NB: I haven't created any specific firewall rules to allow the other working devices on the LAN. Traffic from the vpn server is to forwarded to the LAN.

Thanks
 

copex

Getting the hang of it
Joined
Feb 15, 2015
Messages
225
Reaction score
79
Location
Cumbria,England
the gateway is not used for a local connection as the traffic is not routed, normally if you can connect locally the you can connect via a vpn as the vpn is a client on the local network.
sometimes the way the client creates the vpn to the host the traffic can be routed and in this case if the gateway would have to be correct to route the traffic.

i would go over to the openWRT forums and post all of your settings to see if some one will help you out.
 

sh500

n3wb
Joined
Feb 11, 2018
Messages
10
Reaction score
4
the gateway is not used for a local connection as the traffic is not routed, normally if you can connect locally the you can connect via a vpn as the vpn is a client on the local network.
sometimes the way the client creates the vpn to the host the traffic can be routed and in this case if the gateway would have to be correct to route the traffic.

i would go over to the openWRT forums and post all of your settings to see if some one will help you out.
Thanks for the reply.

This seems only to be affecting the NVR as I am able to access all the other devices within my LAN from the same VPN connection. They all have the same LAN gateway (the router's LAN side). I just thought there may have been something about the Hikvision kit that required it to work.

I am even able to access those Hikvision cameras that are not directly connected to the NVR POE switch - i.e that have a regular LAN IP address (the same range that the NVR is on). The network settings on the individual cameras as the same as the NVR.
 
Last edited:

sh500

n3wb
Joined
Feb 11, 2018
Messages
10
Reaction score
4
Just an update:

I finally found the cause of the issue. I am using a fibre Plusnet Hub One router which then connects to my OpenWRT (LEDE) router, then to the LAN. Although the firewall on the Hub One is switched off (and DMZ on), you still need to explicitly forward required ports. I had originally forwarded only UDP on 1194, but I have now just also forwarded TCP. I am now able to connect to the Hikvision NVR (web config and iVMS app).
 
Top