question

gnagflow avatar image
gnagflow asked

remote console enabled and online but no access

Hi I enabled the VRM remote console, it is online, enabled 2 way communication and disabled password check, updated to the newes firmware at a new system, but cant get remote access - access to remote console only within the home-network by ip.

I need a remote access and it doesnt work. Someone any idea what the problem is?

Thank you!

1668498480971.png

VRM
1668498480971.png (39.9 KiB)
9 comments
2 |3000

Up to 8 attachments (including images) can be used with a maximum of 190.8 MiB each and 286.6 MiB total.

Matthias Lange - DE avatar image Matthias Lange - DE ♦ commented ·
What error do you get?
0 Likes 0 ·
gnagflow avatar image gnagflow Matthias Lange - DE ♦ commented ·

cant connect to GX device .. , unfortunately its on customer site whicht takes 1,5h to drive there so i cannot change any settings ..1668505179483.png

0 Likes 0 ·
1668505179483.png (28.6 KiB)
gnagflow avatar image gnagflow commented ·

Today i worked 3 hours to get the VRM remote running… no chance made everything…. I have many many systems running and everywhere it works … and i have to say i have experience…


PROBLEM: remote VRM is not working but DASHBOARD is working

ALSO: ssh access is not working

SYSTEM CONFIGURATION: MP2-GX with REC-BMS on CAN Bus and MPPT on VE Direct, Fronius Connection via LAN/WLAN


what did i do:

- remote console pw check and disable and reboot

- firmware downgrade from 3.07 to 2.92

- manually set ip address and router and dns address (dns=router), and set automatically in GX

- checked dhcp server on router, everything is alright, the ip range as well it is working

- tried on lan and wlan

- tried to use the handy hotspot to check if the problem is a router setting, does not work via handy hotspot either

- disabled all firewalls on router

- tried to Change DNS server to router address, than changed to 8.8.8.8

- tried many GX reboots after every change

- tried two way communication disable and enable and restart several times

- tried enable/disable https

- tried to restart router several times

-changed vrm protocol from 15min to 1min

. I tested the URL's (https://vncrelay.victronenergy.com & https://vncrelay2.victronenergy.com/) and it returned "Error Response" which is to expected.

- tried on many different devices, different browsers, different locations, different internet providers To get access

-went through all the troubleshooting sections on victron online manual 9.3 9.4

https://www.victronenergy.com/media/pg/Cerbo_GX/en/vrm-portal.html#UUID-5667f877-3cf4-18d8-3f43-2e6ab2843066





SSH Problem:

- tried several times to switch between superuser and normal user and reboot

- tried ssh access within the network within the same ip range from different devices - no acces port 22 refused

- tried to switch between automatic and manual network settings


PROBABLY: SSH PROBLEM and REMOTE VRM ACCESS PROBLEM has the same cause.


WHAT is WORKING?

- access to remote console on lan via IP

-DASHBOARD via Internet (MQTT works well)

- there are no error messages, vrm online …


0 Likes 0 ·
Stefanie (Victron Energy Staff) avatar image Stefanie (Victron Energy Staff) ♦♦ gnagflow commented ·
Sieht mir nach einem Netzwerkproblem aus (firewall?), bei dem bestimmte Ports geblockt werden. Die Tatsache, dass das VRM Dashboard funktioniert, zeigt dass die 2-Wege-Kommunikation zumindest soweit funktioniert. Da hilft nur selbst dorthin zufahren und schauen was genau nicht geht. Ich sehe jetzt kein Victron-Problem.
0 Likes 0 ·
gnagflow avatar image gnagflow Stefanie (Victron Energy Staff) ♦♦ commented ·
Hallo Stefanie, danke für deine Antwort. Ja genau das hatte ich auch vermutet! Hatte aber heute auf der Anlage mit TeamViewer Zugriff und mir die Routereinstellungen und das Netzwerk angesehen. Der Venus hängt direkt per WLAN am T-Mobile UMTS Router. Im Router sind keine Firewalleinstellungen aktiviert. Ich habe dann noch alles deaktiviert was möglich war. Router und Venus sind im selben Netzwerk. Ich kann vom Heimnetzwerk nicht am Venus per SSH zugreifen und die Remote VRM geht auch nicht. Wir haben den Venus dann auch über einen Handy Hotspot angeschlossen, keine Veränderung. Ich kann den Venus im Netzwerk ping-en. Der DHCP Server im Router ist richtig eingestellt. Die IP Adressen passen. Der Router hat keine Firewall, das MP2-GX ist frisch aus der Schachtel, alles upgedated. Kann hier ein anderes Gerät das im Netzwerk hängt irgendwie die Ports blockieren? Wie findet man die Ursache? Warum geht der SSH Zugriff nicht, obwohl ich im VENUS x-fach versucht habe per SUPERUSER freizugeben, inkl. vergebenen Passwort. Die VRM soll auch per SSH laufen, also vermute ich dass es am SSH ein Problem gibt.

Wäre doch komisch wenn der TMOBILE Anbieter irgendwo da nach dem Router den Netzwerkverkehr bzw. den SSH Port blockiert, oder gibt es das, dass das TMOBILE Service hier das Problem ist!? Wäre doch gar nicht üblich und am Handy Hotspot ging's ja auch nicht - war allerdings auch eine T-Mobile Karte.

Dachte dann, vielleicht gibts ein Problem mit dem DNS Server, änderte von der Gateway Adresse zum 8.8.8.8 und dann auf einen von T-Mobile vorgegeben DNS Server. Alles ohne Erfolg.

Irgendwie scheinen entweder die Ports blockiert oder der VENUS zu zicken, aber ohne SSH Zugriff auf das Gerät weiß ich nicht wie ich mich weiter das Problem eingrenzen soll.

danke,

lg


0 Likes 0 ·
Stefanie (Victron Energy Staff) avatar image Stefanie (Victron Energy Staff) ♦♦ gnagflow commented ·

Ich kann mir jetzt nicht vorstellen, was das zicken soll. Steht die Verbindung und sind alle notwendigen Ports (Standardports) offen, geht die Verbindung inkl. SSH-Zugang (vorausgesetzt root access ist aktiviert).

Gäbe es ein ernsthaftes Problem mit Venus OS in diesem Bezug, hätten wir bereits mehr darüber hier in der Community gelesen.

Es gibt noch die Möglichkeit über die serielle Konsole an das System heranzukommen (ohne TCP). Wie das geht, ist in dem oben verlinkten Dokument erklärt.


0 Likes 0 ·
John Leslie avatar image John Leslie Stefanie (Victron Energy Staff) ♦♦ commented ·

Hi @gnagflow. If your site is using a cellular router to gain Internet connectivity, providers like T-Mobile use Carrier-Grade NAT that typically prevent any kind of inbound-initiated connections from the Internet. So I would not expect direct SSH from the Internet -> T-Mobile -> Cerbo to work out of the box. I had that exact problem with SSH & direct http connectivity to Cerbo's Remote Console. To get around it, I setup a VPN connection from the installation router out to a cloud service I can configure. I then setup the routing (&/or port mapping) to get SSH traffic through to the Cerbo from my well-known IP locations on the Internet.


For the Cerbo Remote Console (venus.local/), I had to permit and route ports 80 & 81 (for websockets traffic).

For Victron's MFD Dashboard (venus.local/app/), I had to open 80 & 9001 (for MQTT traffic).


You have probably already confirmed the basics, and I know you are 1.5 hours away from your installation (sorry!). But if not, I suggest you first make sure that access to the Cerbo Remote Console & MFD app via HTTP and SSH to the Cerbo console are both working locally when directly connected to the installation LAN before troubleshooting outwards.


Is VRM data logging working for your installation? That should be working before you attempt Remote Console via VRM. I believe, VRM data logging connections are initiated from the Cerbo-side and thus work over cellular Internet 'inside-out' without any special configuration, as all 'inside', Cerbo-initiated connections are not affected by the carrier's NAT'ing restrictions.

What 'Connection Error' is displayed on Cerbo's Settings -> VRM online Portal page?

untitled-2.jpg

I also believe that Victron has implemented some clever coding such that the Remote Console via VRM works despite any firewalls, carrier NAT'ing that might be in the middle. I believe they do this by initiating all connections from the Cerbo side.

So, can you confirm local LAN access is working for Remote Console and SSH and that basic VRM data logging is working without any errors?

Hope this helps. John

0 Likes 0 ·
untitled-2.jpg (101.6 KiB)
obi-o avatar image obi-o commented ·
Ich habe das gleiche Problem, SSH und Remote über VRM nicht möglich. Mutiplus2GX, Root, VRM ohne Fehlermeldungen (Dashboard funktioniert). Im gleichen Netz habe ich eine Venus Installation auf einem Raspberry, dort funktioniert alles so wie es soll.



@gnagflow : Hast du eine Lösung für das Problem gefunden?

0 Likes 0 ·
gnagflow avatar image gnagflow obi-o commented ·
Hi, sorry i couldnt find the problem.
0 Likes 0 ·
4 Answers
klubags avatar image
klubags answered ·

Hello, I am experiencing the same issue (Remote Console accessible locally but not through the internet VRM portal).

My customer is IT oriented and discovered that the moment when Remote Console is requested in the VRM portal, there is a "web socket connection failure". Here is the message:

novnc.js:1332 WebSocket connection to 'wss://vncrelay7.victronenergy.com/websockify?token=XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX&identifier=XXXXXXXXXXXX' failed:

It should be noted that the first series of "X"s is an alpha numeric adresss (sensitive information) and the second series of "X"s is the VRM ID of the Multiplus II GX device (updated to firmware version 2.92)

Other relevant information:

The Multiplus II GX has replaced a Color Control GX which had no issues with Remote Console access

The process followed is as described in the video

https://www.youtube.com/watch?v=3tPLHot7TAc

It is possible that I did not correctly confirm that the new device was sending data (20 seconds into the video). However I can confirm that the new Multiplus II GX was recognised in the VRM Portal and has been sending data ever since the replacement.


So the only limitation remains the ability to access the Remote Console via the VRM portal when using an internet connection.


Any help would be much appreciated.









2 |3000

Up to 8 attachments (including images) can be used with a maximum of 190.8 MiB each and 286.6 MiB total.

klubags avatar image
klubags answered ·

Just a post note to my previous post.

In the VRM portal, for the Gateway (the GX device in the device list), the field "Remote Console on VRM" reads "Enabled and up" rather than "Enabled and Online". Not sure if this is pertinent or not.



2 |3000

Up to 8 attachments (including images) can be used with a maximum of 190.8 MiB each and 286.6 MiB total.

obsidian avatar image
obsidian answered ·

Curious if anyone at Victron has suggestions on this issue - my company has been testing remote console and now see multiple units failing to allow remote console. It's frustrating because there is little no to no information or methods to see why this fails. Anyone have any clues??

2 |3000

Up to 8 attachments (including images) can be used with a maximum of 190.8 MiB each and 286.6 MiB total.

flenis avatar image
flenis answered ·

Just want to add my voice and case to the ones above - New install but same symptoms. Would love some help.

New Cerbo-S GX on Version 2.92. Connected over Wifi. Remote console accessible by LAN but not from VRM. Remote console listed as "Enabled and up" in VRM. Logging in VRM works fine. Running Ubiquiti Unifi router at home.

("Enabled and online" is reported for Remote support so maybe that's the source of confusion referred to in a previous post)

Have tested setting a password and rebooting. Removing the password and rebooting. Disabling Remote console on VRM and on LAN, rebooting, enabling and rebooting.

2 |3000

Up to 8 attachments (including images) can be used with a maximum of 190.8 MiB each and 286.6 MiB total.