ACCESSLocksmiths

Video intercoms · Dahua 2-wire field guide

Dahua 2-wire intercom setup: the field-tested procedure and seven failure modes

A practical commissioning guide for the DHI-VTO3222E-P villa door station, VTH1550CHW-2-S1 indoor monitor and VTNS2003B-2 2-wire switch — the documentation gaps we hit, the root cause of each failure, and the exact fixes.

Part 1 of 7 · By Gareth Barber, Owner & Head Locksmith, Access Locksmiths · Published 2026-10-05

Written from one real villa deployment. Network addresses, credentials, door codes and serial numbers have been removed or replaced with generic examples. Firmware and generations differ — check each step against your own models.

The short version

Dahua's 2-wire IP intercom range lets you modernise an entrance where only two conductors run to the gate. Once working it is excellent: video, keypad PIN, RFID fobs, calls to a phone and remote unlock. Getting there is where installers lose hours.

The failure is rarely hardware. It is almost always addressing. Three devices — a door station, an indoor monitor and a "hub" that has no IP address at all — have to end up on one subnet, with a SIP relationship between the two IP hosts and a working internet path for the door station. The manuals describe each device in isolation and never give the commissioning order, and the app everyone reaches for cannot set a door code. That one undocumented fact causes most of the pain.

The finished job: a Dahua DHI-VTO3222E-P door station on the gate pillar. Tap the fob, the gate releases. Our own footage.

1. The hardware, and what each box actually does

RoleModel (as deployed)What it isNetwork behaviour
Gate / door stationDHI-VTO3222E-P2-wire IP villa outdoor station. Mechanical 12-key keypad, Mifare card reader, 2 MP camera. Unlock by card, password or remote. Web configuration; also has RJ-45 + PoE.An IP host (web UI, SIP server), powered and networked over the two wires.
Indoor monitorVTH1550CHW-2-S17-inch 2-wire IP indoor monitor. On-screen settings, Room No., VTO list, monitor and call.An IP host on the same subnet; SIP client.
“Hub”VTNS2003B-22-wire power + signal switch (48 V DC in). One 2-wire device port, cascade ports, 2× RJ-45.No IP address and no web UI. Injects power and bridges the 2-wire bus to Ethernet.

Consequence: only two of the three boxes have an IP. The switch will never appear in a port scan — identify it by its LEDs.

Switch LED cheat-sheet: POWER solid red = powered. RUN flashing green = healthy. E1 flashing green = uplink (router side) OK. E2 flashing green = cascade OK. P flashing green = a door station or monitor is talking on the bus. P solid or off = no 2-wire device seen — a wiring or bus fault.

2. The mental model

        HOUSE LAN (e.g. 192.168.0.0/24)

   [Wi-Fi / phone] ---- [Router] ---- [Wi-Fi extender / AP]
                                             |
                                   [ VTNS2003B-2 "hub" ]     one RJ-45 uplink; NO IP
                                             |
                          2-wire bus (48 V + network over two wires)
                           |                               |
                  [ DHI-VTO3222E-P ]              [ VTH1550CHW-2-S1 ]
                   gate door station                indoor monitor
                   IP host + SIP server             IP host + SIP client

Five truths the manuals don't state plainly:

  1. The two wires carry both power and data. The VTNS2003B-2 is effectively a powerline-to-Ethernet bridge. There is no separate data pair.
  2. The hub has no IP. It is invisible to ping, to a scanner and to the app.
  3. Door station and monitor must share one subnet. The door station is the SIP server and the monitor registers to it as a Room No. (e.g. 9901). On our deployment the two were registered to each other; whichever arrangement your firmware uses, the two SIP addresses must point at each other's current IPs.
  4. Basic intercom works with no internet. Call, monitor, unlock and PIN all run over the 2-wire bus and the LAN. Internet is only needed for the mobile app.
  5. The keypad PIN lives on the door station, set in its web UI — not on the monitor screen and not in the app.

3. The documentation gaps we confirmed

  1. No end-to-end commissioning order across the three manuals. Nothing says addressing and SIP must be fixed in a particular sequence.
  2. The hub's IP-less, bridge-only nature is buried. Installers reasonably expect a "hub" to be something you can log into.
  3. The door code cannot be set from the monitor or the app. The app's Access screen only views unlock records and performs a remote unlock.
  4. The monitor's "VTO Set" list is undocumented — in particular that the entry's address is what the Monitor button uses, and that an entry pointing at the monitor's own IP produces "Failed to monitor. The network is abnormal."
  5. Conflicting factory defaults. Different generations default to 192.168.1.108 or 192.168.1.110, and a monitor and door station can both ship on 192.168.1.108.
  6. No guidance on Wi-Fi extenders. Most extender modes create a second subnet, which silently breaks discovery and the cloud path.
  7. The monitor can be a DHCP client whose address silently moves, breaking the SIP link with no obvious warning.

4. The seven failure modes

SymptomRoot causeFix
Door code can't be set; “you need an app”The keypad PIN is a door-station Public Password; the app can't write itSet it in the door station web UI (Part 3)
Mobile app never works; door station shows cloud OfflineDoor station on a stale subnet with a dead gateway/DNS, so no route to the cloudMove it onto the house LAN with a valid gateway and DNS, then confirm VSP_PaaS.Online = true
Monitor: “Failed to monitor. The network is abnormal.”The monitor's VTO Set entry points at the monitor's own IP, or a stale door-station IPSet the GATE entry to the door station's current IP (Part 2)
Intermittent failure after re-mounting or a power-cycleMonitor was on DHCP; its address movedMake the monitor's IP static
Nothing discovered on the LAN; app same-network discovery failsWi-Fi extender in router mode (a second subnet) or multicast filteringPut the extender in bridge/AP mode, or uplink the hub straight to the router
Two Dahua devices unreachable or flappingDuplicate default IP (e.g. both at 192.168.1.108)Give each device a unique static IP
Door station responds but the monitor is invisible to a scanThe monitor exposes no TCP services a scanner looks for (SIP is UDP/5060)Discover by ARP/MAC OUI and the door station's SIP config, not by port scan

5. The working commissioning procedure (order matters)

Addressing convention used here: the client LAN is a generic 192.168.0.0/24; the Dahua factory subnet is 192.168.1.x. Substitute your own.

5.1 Physical and LED check

5.2 Decide the addressing before touching a device menu

5.3 Find the devices

5.4 Give the door station a working network path

Set IP, mask, gateway and DNS, reboot, then check /cgi-bin/configManager.cgi?action=getConfig&name=VSP_PaaS returns Online=true. That is the gate to the mobile app.

5.5 Fix the SIP relationship

5.6 Set the keypad door code

On the door station web UI: Local Device Config → Access Control → Config → Public Password → Setting → Add. Enter a user name and a 4–6 digit code, apply, then test at the keypad with # code #. The DMSS app cannot do this. Detail in Part 3.

5.7 Commission cards and fobs

Enable card reading under Card Settings if required, issue the cards through the door station, and test every fob against the live device.

5.8 Mobile app

Add the door station to DMSS (Part 6). It must already be cloud Online from step 5.4.

5.9 Make the addressing permanent

Set both IP hosts to static — the monitor especially, as it often defaults to DHCP — and record the addresses and credentials for the handover.

5.10 Acceptance test

6. Talking to the devices directly

Two interfaces matter. The door station answers the legacy CGI over HTTP Digest:

# identify
curl -k --digest -u admin:PW "https://<VTO-IP>/cgi-bin/magicBox.cgi?action=getDeviceType"

# read a whole config section
curl -k --digest -u admin:PW "https://<VTO-IP>/cgi-bin/configManager.cgi?action=getConfig&name=Network"
#   -> Network | SIP | VTOInfo | RemoteDevice | AccessControlGeneral | VSP_PaaS | ...

# write (brackets in names need curl -g to disable globbing)
curl -g -k --digest -u admin:PW \
  "https://<VTO-IP>/cgi-bin/configManager.cgi?action=setConfig\
&Network.eth0.IPAddress=192.168.0.60&Network.eth0.DefaultGateway=192.168.0.1\
&Network.eth0.DnsServers[0]=192.168.0.1"

# set the door code
curl -k --digest -u admin:PW \
  "https://<VTO-IP>/cgi-bin/configManager.cgi?action=setConfig&AccessControlGeneral.CommonPassword=<CODE>"

The indoor monitor exposes only the newer RPC2 JSON-RPC API — covered in Part 5.

Discovery that actually worked

7. Quick troubleshooting matrix

SymptomFirst checkThen
Monitor: “network abnormal”Is the monitor's GATE entry the door station's current IP?Fix the SIP server on the monitor; reboot both
App: door station OfflineAre the door station's gateway and DNS valid?getConfig name=VSP_PaaS → Online
Keypad code won't workWas the PIN added as a Public Password on the door station?Re-add in the web UI; test #code#
Devices flapping after a rebootIs either IP host on DHCP?Set static
Nothing found on the LANIs the hub uplinked to the router or a bridge-mode AP?Fix the extender mode
Two devices on the same IPFactory defaults collidingAssign unique statics
Monitor invisible to scansNormal — SIP is UDPDiscover by ARP/MAC and the door station's SIP config

8. Defaults, ports and config keys

Default addresses and passwords are listed so you can find a device on the bench. A device left on a default password is an open door — set a strong admin password at commissioning and record it in the handover pack.
ItemValue
Door station default IP192.168.1.108 (current generation) or 192.168.1.110 (older villa generation)
Monitor default IP192.168.1.108 — collides with the door station; change one
Legacy default credentialsuser admin; passwords seen historically admin, 002236, 888888, 123456
Monitor settings password (older generation)888888
New-generation initial password rules8–32 characters, at least two character classes
Keypad unlock (public PIN)# code #
Private (per-resident) coderoom number (6 digits) + personal password
PurposePort(s)
HTTP / HTTPS80 / 443
RTSP554
Dahua SDK37777 (TCP), 37778 (UDP)
Monitor / camera stream5000
SIP5060 (UDP/TCP)
Dahua cloud (P2P)TCP 8800–8803, 8900–8903, 12366, 8180; all outbound UDP; domains easy4ipcloud.com, easy4ip.com, devaccess.easy4ipcloud.com

Config keys used (door station, CGI): Network.eth0.* · SIP.* (IsMainVTO, SIPServer, OutboundProxy, SIPServerID, UserID) · AccessControlGeneral.CommonPassword · VTOInfo.* · RemoteDevice.* · VSP_PaaS.Online · MobilePhoneApplication.PushNotificationEnable.

In Brisbane and would rather it was just done? Access Locksmiths installs, repairs and commissions video intercoms and access control of all makes, with a written handover. Call 0404 159 369 or get a quote by text.

Written from one real deployment. Client-identifying details have been removed; technical values are generic examples. Firmware and hardware generations differ — verify each step against your own models. Corrections are welcome and will be published with attribution.

📞 Call nowBook online