timbo343 Posted January 11, 2024 Posted January 11, 2024 We've been handed a wireless door bell (the EUKI J9) model and asked if we can get it to work via the Smoothwall. So, here's what we have done. - Installed the Cloudot app on to our phone, turned on Bluetooth and Location as requested via the app and had to make sure the phone was connected to the SSID the doorbell is going to sit on. - Now we've added the SSID details we scan the QR code on the phone and this sets up the DoorBell. We can see the Doorbell has an IP address from DHCP so that's working as it should. Now on to the next part - the Smoothwall. - The IP address of the doorbell is 192.168.1.10/24 (for arguments sake). - A firewall rule has been created so that anything from 192.168.1.10 to external is accepted and also anything from external to 192.168.1.10 is accepted - all ports open. - A Web Proxy rule has been set so that IP address 192.168.1.10 so that unauth requests are Network Admins - I've found the URLs the camera is talking to - https://apis-eu-frankfurt.cloudedge360.com/ and http://meari-eu.oss-eu-central-1.aliyuncs.com/alertImage/102999892/105379201/105379201-20240111071754-945406.jpg. The latter i guess being the image when the doorbell button is pressed. - The URLs have been added to a category, this category has been added to: > Proxy Exceptions > HTTPS Do Not Inspect > Guardian HTTP policies - Do not filter Result is (phone on 4G) - when phone is using it's data connection, the doorbell in the app reports as Offline. - When the doorbell button is pressed, the phone is notified and user can answer tap the answer button however the app goes not initiate the intercom which is two way audio and the web camera. Any help on this would be great.
drewp Posted January 11, 2024 Posted January 11, 2024 You could try a web proxy exception for the ip address of the doorbell - Guardian>Web filter>Exceptions
tom_newton Posted January 11, 2024 Posted January 11, 2024 Yup - you want to except it completely, some of these IoT-y things hate being proxied. Particularly doorbells. It's the video.
timbo343 Posted January 11, 2024 Author Posted January 11, 2024 I should have said that this doorbell is on a VLAN / SSID with transparent proxies. The Web Filter > Exceptions won't make a difference will it?
timbo343 Posted January 11, 2024 Author Posted January 11, 2024 So after all that, i've got it working! In the end the device IP address kept changing so MAC address > Static IP worked. The dam thing keeps wanting to connect to so many different ports. I guess that what happens when you buy cheap Chinese stuff off amazon rather than a well known brand! Taken back / turned off all the rules for HTTP and HTTPS inspection though the default category for these is the API [deprecated] Category so i might have to keep the custom category there for now. Removed the category from Proxy Exceptions but left the rule in for Web Proxy - no auth use network managers for unauth requests.
MatthewL Posted January 11, 2024 Posted January 11, 2024 I would only create an outbound rule in this instance, it wont need an inbound for any external to door bell, in this instance if you needed it you would need a NAT. Look at the outbound after doing any rule, analyse the logs and lock it down if no firewall requirements document is provided which is unlikely. Get is restricted, that is how I work when I get something that does have a document as such.
timbo343 Posted January 11, 2024 Author Posted January 11, 2024 I would only create an outbound rule in this instance, it wont need an inbound for any external to door bell, in this instance if you needed it you would need a NAT. Look at the outbound after doing any rule, analyse the logs and lock it down if no firewall requirements document is provided which is unlikely. Get is restricted, that is how I work when I get something that does have a document as such.That's what ive done. It's a nasty bit of kit once you start seeing where the device is talking to along with no static port(s) being used. It's certainly not like a RING which i've seen specific ports to be opened.
MatthewL Posted January 11, 2024 Posted January 11, 2024 I found that out once when I had to another similar thing for a friend, glad it doesn't sit on my network, don't feel comfortable with what I don't have control have hence the lock down.
timbo343 Posted January 11, 2024 Author Posted January 11, 2024 (edited) I found that out once when I had to another similar thing for a friend, glad it doesn't sit on my network, don't feel comfortable with what I don't have control have hence the lock down.Aye. Just have to let the headteacher know of the risk. Even though the school has a paxton system, an intercom system would have been safer but the price of the intercom is outrangeous - risk vs price again. Edited January 11, 2024 by timbo343
MatthewL Posted January 12, 2024 Posted January 12, 2024 It will come back and bite them, it always does.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now