Video intercoms · Dahua 2-wire field guide
A practical commissioning guide for the DHI-VTO3222E-P villa door station, VTH1550CHW-2-S1 indoor monitor and VTNS2003B-2 2-wire switch — the documentation gaps we hit, the root cause of each failure, and the exact fixes.
Part 1 of 7 · By Gareth Barber, Owner & Head Locksmith, Access Locksmiths · Published 2026-10-05
Dahua's 2-wire IP intercom range lets you modernise an entrance where only two conductors run to the gate. Once working it is excellent: video, keypad PIN, RFID fobs, calls to a phone and remote unlock. Getting there is where installers lose hours.
The failure is rarely hardware. It is almost always addressing. Three devices — a door station, an indoor monitor and a "hub" that has no IP address at all — have to end up on one subnet, with a SIP relationship between the two IP hosts and a working internet path for the door station. The manuals describe each device in isolation and never give the commissioning order, and the app everyone reaches for cannot set a door code. That one undocumented fact causes most of the pain.
| Role | Model (as deployed) | What it is | Network behaviour |
|---|---|---|---|
| Gate / door station | DHI-VTO3222E-P | 2-wire IP villa outdoor station. Mechanical 12-key keypad, Mifare card reader, 2 MP camera. Unlock by card, password or remote. Web configuration; also has RJ-45 + PoE. | An IP host (web UI, SIP server), powered and networked over the two wires. |
| Indoor monitor | VTH1550CHW-2-S1 | 7-inch 2-wire IP indoor monitor. On-screen settings, Room No., VTO list, monitor and call. | An IP host on the same subnet; SIP client. |
| “Hub” | VTNS2003B-2 | 2-wire power + signal switch (48 V DC in). One 2-wire device port, cascade ports, 2× RJ-45. | No IP address and no web UI. Injects power and bridges the 2-wire bus to Ethernet. |
Consequence: only two of the three boxes have an IP. The switch will never appear in a port scan — identify it by its LEDs.
Switch LED cheat-sheet: POWER solid red = powered. RUN flashing green = healthy. E1 flashing green = uplink (router side) OK. E2 flashing green = cascade OK. P flashing green = a door station or monitor is talking on the bus. P solid or off = no 2-wire device seen — a wiring or bus fault.
HOUSE LAN (e.g. 192.168.0.0/24)
[Wi-Fi / phone] ---- [Router] ---- [Wi-Fi extender / AP]
|
[ VTNS2003B-2 "hub" ] one RJ-45 uplink; NO IP
|
2-wire bus (48 V + network over two wires)
| |
[ DHI-VTO3222E-P ] [ VTH1550CHW-2-S1 ]
gate door station indoor monitor
IP host + SIP server IP host + SIP client
Five truths the manuals don't state plainly:
ping, to a scanner and to the app.9901). On our deployment the two were registered to each other; whichever arrangement your firmware uses, the two SIP addresses must point at each other's current IPs.192.168.1.108 or 192.168.1.110, and a monitor and door station can both ship on 192.168.1.108.| Symptom | Root cause | Fix |
|---|---|---|
| Door code can't be set; “you need an app” | The keypad PIN is a door-station Public Password; the app can't write it | Set it in the door station web UI (Part 3) |
| Mobile app never works; door station shows cloud Offline | Door station on a stale subnet with a dead gateway/DNS, so no route to the cloud | Move it onto the house LAN with a valid gateway and DNS, then confirm VSP_PaaS.Online = true |
| Monitor: “Failed to monitor. The network is abnormal.” | The monitor's VTO Set entry points at the monitor's own IP, or a stale door-station IP | Set the GATE entry to the door station's current IP (Part 2) |
| Intermittent failure after re-mounting or a power-cycle | Monitor was on DHCP; its address moved | Make the monitor's IP static |
| Nothing discovered on the LAN; app same-network discovery fails | Wi-Fi extender in router mode (a second subnet) or multicast filtering | Put the extender in bridge/AP mode, or uplink the hub straight to the router |
| Two Dahua devices unreachable or flapping | Duplicate default IP (e.g. both at 192.168.1.108) | Give each device a unique static IP |
| Door station responds but the monitor is invisible to a scan | The monitor exposes no TCP services a scanner looks for (SIP is UDP/5060) | Discover by ARP/MAC OUI and the door station's SIP config, not by port scan |
Addressing convention used here: the client LAN is a generic 192.168.0.0/24; the Dahua factory subnet is 192.168.1.x. Substitute your own.
P LED flashing green.192.168.1.x (a USB-Ethernet adapter into the hub works well), or scan the LAN.WEB. Expect two hosts; the hub will not appear.GET /cgi-bin/magicBox.cgi?action=getDeviceType returns e.g. type=DHI-VTO3222E-P.Set IP, mask, gateway and DNS, reboot, then check /cgi-bin/configManager.cgi?action=getConfig&name=VSP_PaaS returns Online=true. That is the gate to the mobile app.
IsMainVTO=1; SIPServer / OutboundProxy = its own IP (or the monitor's, where the two register to each other).SIPServer, OutboundProxy, Proxy and STUNServer = the door station's current IP.VTOInfo / RemoteDevice): the GATE entry's address = the door station IP, enabled. Disable any entry at 0.0.0.0 or at the monitor's own IP.On the door station web UI: Local Device Config → Access Control → Config → Public Password → Setting → Add. Enter a user name and a 4–6 digit code, apply, then test at the keypad with # code #. The DMSS app cannot do this. Detail in Part 3.
Enable card reading under Card Settings if required, issue the cards through the door station, and test every fob against the live device.
Add the door station to DMSS (Part 6). It must already be cloud Online from step 5.4.
Set both IP hosts to static — the monitor especially, as it often defaults to DHCP — and record the addresses and credentials for the handover.
Two interfaces matter. The door station answers the legacy CGI over HTTP Digest:
# identify
curl -k --digest -u admin:PW "https://<VTO-IP>/cgi-bin/magicBox.cgi?action=getDeviceType"
# read a whole config section
curl -k --digest -u admin:PW "https://<VTO-IP>/cgi-bin/configManager.cgi?action=getConfig&name=Network"
# -> Network | SIP | VTOInfo | RemoteDevice | AccessControlGeneral | VSP_PaaS | ...
# write (brackets in names need curl -g to disable globbing)
curl -g -k --digest -u admin:PW \
"https://<VTO-IP>/cgi-bin/configManager.cgi?action=setConfig\
&Network.eth0.IPAddress=192.168.0.60&Network.eth0.DefaultGateway=192.168.0.1\
&Network.eth0.DnsServers[0]=192.168.0.1"
# set the door code
curl -k --digest -u admin:PW \
"https://<VTO-IP>/cgi-bin/configManager.cgi?action=setConfig&AccessControlGeneral.CommonPassword=<CODE>"
The indoor monitor exposes only the newer RPC2 JSON-RPC API — covered in Part 5.
WEB; SDK port 37777; RTSP 554; stream port 5000.| Symptom | First check | Then |
|---|---|---|
| Monitor: “network abnormal” | Is the monitor's GATE entry the door station's current IP? | Fix the SIP server on the monitor; reboot both |
| App: door station Offline | Are the door station's gateway and DNS valid? | getConfig name=VSP_PaaS → Online |
| Keypad code won't work | Was the PIN added as a Public Password on the door station? | Re-add in the web UI; test #code# |
| Devices flapping after a reboot | Is either IP host on DHCP? | Set static |
| Nothing found on the LAN | Is the hub uplinked to the router or a bridge-mode AP? | Fix the extender mode |
| Two devices on the same IP | Factory defaults colliding | Assign unique statics |
| Monitor invisible to scans | Normal — SIP is UDP | Discover by ARP/MAC and the door station's SIP config |
| Item | Value |
|---|---|
| Door station default IP | 192.168.1.108 (current generation) or 192.168.1.110 (older villa generation) |
| Monitor default IP | 192.168.1.108 — collides with the door station; change one |
| Legacy default credentials | user admin; passwords seen historically admin, 002236, 888888, 123456 |
| Monitor settings password (older generation) | 888888 |
| New-generation initial password rules | 8–32 characters, at least two character classes |
| Keypad unlock (public PIN) | # code # |
| Private (per-resident) code | room number (6 digits) + personal password |
| Purpose | Port(s) |
|---|---|
| HTTP / HTTPS | 80 / 443 |
| RTSP | 554 |
| Dahua SDK | 37777 (TCP), 37778 (UDP) |
| Monitor / camera stream | 5000 |
| SIP | 5060 (UDP/TCP) |
| Dahua cloud (P2P) | TCP 8800–8803, 8900–8903, 12366, 8180; all outbound UDP; domains easy4ipcloud.com, easy4ip.com, devaccess.easy4ipcloud.com |
Config keys used (door station, CGI): Network.eth0.* · SIP.* (IsMainVTO, SIPServer, OutboundProxy, SIPServerID, UserID) · AccessControlGeneral.CommonPassword · VTOInfo.* · RemoteDevice.* · VSP_PaaS.Online · MobilePhoneApplication.PushNotificationEnable.
Written from one real deployment. Client-identifying details have been removed; technical values are generic examples. Firmware and hardware generations differ — verify each step against your own models. Corrections are welcome and will be published with attribution.