This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Port Forwarding for RTSP Stream

Hello,

I have read through and followed the suggestions on other posts regarding port forwarding (NAT) within UTM 9 however, I cannot seem to get things to work.

I have three internal cameras with which I need to allow external access to their RTSP streams. The internal url for these feeds are as follows:

rtsp://192.168.1.30:554/11
rtsp://192.168.1.28:554/11
rtsp://192.168.1.32:554/11

Using my single external IP address, I will need to specify a different port and then forward for each camera such as:

rtsp://200.13.12.42:2007 => rtsp://192.168.1.30:554/11
rtsp://200.13.12.42:2008 => rtsp://192.168.1.28:554/11
rtsp://200.13.12.42:2009 => rtsp://192.168.1.32:554/11

I have tried to accomplish this numerous ways and I am still unable to view these streams externally. Internally, the streams function perfectly. How do I go about configuring this correctly? Thanks in advance for any assistance.


This thread was automatically locked due to age.
  • VLC, works perfectly on the LAN side of things.
  • have you any rule in Application Control
  • Application control? Is this a setting within the Sophos? 

    I aplogize for my overall ignorance regarding the Sophos software/environment. I am a software developer working on an application that will use a VLC plugin to view these camera streams. Our network admin is not able to look at this until next week and I am at a standstill until I can access these cameras externally. So, I really do appreciate the assistance!
  • Yes  application controll is inside Sophos in Web Protection
  • Ok so I have checked the firewall log and this is what I see:



    FYI, that is not the firewall log, that is a report.

    Barry
  • This is a customer of mine, I'm looking at it today.  I'll let you guys know what I find, if there's a solution.  [:)]

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

  • Here's the deal; rtsp does not traverse a double nat, due to how the protocol works... have to have a device on the other end that supports TURN to do that.. and these cameras don't, therefore I gave them some alternate options to achieve their particular goal.  Not a defect of the utm, rather a limitation of rtsp and firewalls in general.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

  • I also do have the same problem with UTM9.308-16

    I have several ip cams in my networks that use RTSP 554 UDP protocol to enable a network stream.

    I use VLC to stream inside the network using the url rtsp://lanip:554/11 that works just fine.

    If I use my external ip or external dns via rtsp://wanip:555/11 or rtsp://username[:P]asword@wanip:554/11 i'm not able to connect!


    I have created a D-NAT rule for accessing the cam using RTSP (UDP) protocol. See attachment

    Firewall logging shows that the rule is accepted and not blocked. See attachment.

    Using a Fritzbox and enabling RTSP there via 554 just works fine.

    Please help
  • Check #1 and #3 through #4 in Rulz - any luck?

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA