• Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular

    Monocle Gateway initializes Axis camera, but Alexa never connects

    Support
    1
    3
    21
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Alzi last edited by

      Hello Monocle Support and Community,

      I need help diagnosing an issue with Monocle Gateway on my Synology NAS. We have completed several troubleshooting steps, but the camera stream still does not appear on Alexa. I would appreciate a targeted diagnosis based on the results below rather than repeating checks that have already been completed.

      1. IP Camera Make and Model

      • Manufacturer: Axis
      • Model: AXIS P3245-LVE
      • Camera IP: 192.168.1.52
      • RTSP port: 554
      • RTSP stream URL: rtsp://192.168.1.52:554/axis-media/media.amp?videocodec=h264
      • Video codec: H.264
      • Monocle camera tag tested: @tunnel

      2. Alexa Devices Tested

      • Alexa app: Running on an iPhone 17
      • Echo device: Amazon Echo Show 8, latest generation

      I initiate the camera request through the Alexa app and also want to view the camera on the Echo Show 8.

      3. NAS, Home Assistant and Network Setup

      • NAS: Synology DiskStation DS220+
      • DSM version: DSM 7.4.1-90080
      • Home Assistant: Running in a Docker container on the Synology NAS, not Home Assistant OS or Supervised
      • Router: FRITZ!Box 6890 LTE
      • LAN subnet: 192.168.1.0/24
      • Router IP: 192.168.1.1
      • Synology network addresses: 192.168.1.128 and 192.168.1.129
      • Monocle Gateway Docker container: monocle-gateway-test
      • Monocle Gateway IP: 192.168.1.199
      • Monocle Gateway port: 443
      • Docker network: monocle_macvlan, using ovs_eth0 as its parent interface
      • Gateway token: Mounted into the container at /etc/monocle/monocle.token

      The previous Monocle Gateway container, monoclecam-monocle-gateway-1, was stopped while testing the current container.

      4. Troubleshooting Steps and Results

      A. Tested the Axis camera directly

      • Access to the camera’s web interface at http://192.168.1.52 works.
      • The camera can be accessed using its existing camera credentials.
      • The direct RTSP stream plays correctly in VLC.
      • The camera has also been added to Home Assistant using its IP address and HTTP connection.
      • The Home Assistant camera preview and full camera view both work.

      Result: The camera itself and its direct RTSP stream appear to be working correctly.

      B. Tried the ONVIF integration

      • We attempted to use ONVIF with the Axis camera.
      • The attempt failed with an authorization error (NotAuthorized) and HTTP 405.
      • We abandoned this approach and continued with the working direct RTSP stream.

      C. Set up Monocle Gateway on Synology

      • Started the monocle-gateway-test Docker container on the Synology NAS.

      • Assigned the gateway the LAN IP address 192.168.1.199.

      • Configured port 443.

      • Mounted the Monocle token into the container.

      • Confirmed in the logs that the gateway connects to Monocle and registers the RTSP server.

      • The gateway reports its hostname as:

        c8e69002-1294-40ed-b29d-d1a68758e33a.mproxy.io

      • The gateway logs show active listeners on ports 443, 8554 and 8555.

      Result: The gateway container is running and registers the camera stream.

      D. Checked DNS and network connectivity

      • From my Windows PC, nslookup resolves the Monocle gateway hostname to 192.168.1.199 through the FRITZ!Box.
      • Added monoclecam.com and the exact gateway hostname to the FRITZ!Box DNS rebinding exception list.
      • Tested a TCP connection from the PC to 192.168.1.199 on port 443.
      • The connection test succeeded.
      • A raw TCP connection using curl to port 443 also established a connection, although it waited for data afterward.

      Result: DNS resolution to the gateway’s private LAN address works on the PC, and TCP port 443 is reachable from the PC. We have not independently verified connectivity from the Echo Show to the gateway.

      E. Requested the camera through Alexa and examined gateway logs

      • The gateway repeatedly logs INITIALIZE RTSP STREAM for the Axis camera.
      • However, it does not log INBOUND RTSP CONNECTION FROM ALEXA.
      • We also do not see the expected subsequent connection messages indicating that an Alexa RTSP client has connected and attached to the stream.
      • Changing the camera tag to @tunnel did not resolve the issue.
      • Alexa Camera History shows InitializeCameraStreams with a URL using the gateway hostname, port 443, and a stream/session identifier.
      • The Alexa stream request specifies H.264 video, 192 × 192 resolution, and DIGEST authentication.

      Result: Alexa appears to initiate the stream setup, and the gateway initializes the stream, but the expected inbound stream connection is missing from the gateway logs.

      F. Tried the gateway’s advertised stream URL in VLC

      • We tried opening the gateway’s advertised RTSP URL in VLC.
      • VLC established a TCP connection to the gateway hostname on port 443.
      • VLC then reported Failed to setup RTSP session, along with a read error.

      We understand that Monocle Gateway may use a secure TLS-based stream that is not directly playable through a standard VLC RTSP connection. Therefore, we do not consider this VLC result conclusive evidence of a gateway failure.

      G. Inspected the gateway’s TCP sockets

      • Inspected /proc/net/tcp from inside the running gateway container.
      • Confirmed listening sockets corresponding to ports 443, 8554 and 8555.
      • The snapshot also showed an established TCP connection to a remote IP address on port 443.

      Result: The gateway has its expected listening sockets and an outbound connection, but this inspection did not establish why the Alexa stream connection is missing.

      5. Current Problem

      The Axis camera works in VLC and Home Assistant. The Monocle Gateway container is running, connects to Monocle, registers the camera, and logs INITIALIZE RTSP STREAM when Alexa requests the stream.

      However, the gateway never logs INBOUND RTSP CONNECTION FROM ALEXA, and the camera image does not appear on the Echo Show 8.

      We have already checked the gateway’s DNS resolution from the PC, confirmed that TCP port 443 is reachable from the PC, added the gateway hostname to the FRITZ!Box DNS rebinding exceptions, tested the @tunnel tag, and inspected the gateway logs and listening sockets.

      6. Questions for Monocle Support

      Could you please help us determine:

      1. Is resolving the gateway’s fully qualified hostname to its private LAN IP (192.168.1.199) through the FRITZ!Box the correct configuration for an Echo Show 8?
      2. Does this symptom indicate that Alexa cannot reach the gateway, or could the failure occur earlier in the Monocle stream initialization process?
      3. Is there a specific gateway log level, diagnostic command, or Alexa-side diagnostic that would identify where the connection fails?
      4. Are there any known compatibility or configuration issues with the latest-generation Echo Show 8, Synology DSM 7.4.1, or a Docker macvlan network?
      5. What is the next targeted diagnostic step, given that the camera stream itself works and the gateway’s port 443 is reachable from a PC?

      We would appreciate a specific recommendation based on these findings. We have already spent considerable time troubleshooting and would like to avoid repeating checks that have been completed.

      Thank you for your help.

      A 1 Reply Last reply Reply Quote 0
      • A
        Alzi @Alzi last edited by

        Update: I tested Monocle Gateway on a Windows PC using a new token and hostname (a3791ebb-580c-45f9-8bb3-820bc71bc50d.mproxy.io). The gateway connects to Monocle and logs INITIALIZE RTSP STREAM, but then reports DNS RESOLVE ERROR: queryA ENODATA for its own hostname. nslookup against public DNS 1.1.1.1 resolves it to 192.168.1.5, while querying the FRITZ!Box DNS at 192.168.1.1 returns no A/AAAA record. The same failure occurs with two Alexa devices. Could you clarify which DNS resolver the gateway uses here and why this lookup returns ENODATA?

        A 1 Reply Last reply Reply Quote 0
        • A
          Alzi @Alzi last edited by

          Update 2 — Solved the DNS Error, but still no Inbound Alexa Connection (Properties Override Active)
          Hello again,
          We have made significant progress on the Windows PC troubleshooting instance and isolated exactly how the gateway handles (and mishandles) settings. Here is the latest diagnostic data:

          1. DNS ENODATA Error Resolved:
          The DNS RESOLVE ERROR: queryA ENODATA on the FRITZ!Box was successfully resolved. The router was strictly blocking the dynamically generated *.mproxy.io subdomains via its DNS Rebind Protection. Adding the root domain mproxy.io as an exception in the FRITZ!Box configuration immediately cleared the error.

          2. Properties Override Implemented:
          We discovered that the Windows gateway executable does not accept command-line arguments (throwing Unsupported command argument(s) for --port or --register). To bypass this and ensure exact binding, we successfully deployed a local monocle.properties file inside the %USERPROFILE%.monocle\ directory. The gateway now successfully initializes with the following explicit overrides:
          • rtsp.host=192.168.1.5
          • rtsp.ssl.port=443
          • rtsp.register.host=192.168.1.5

          3. Camera Stream Optimization (Axis Specific):
          To ensure absolute Alexa compatibility, the Axis P3245-LVE stream profile has been strictly optimized directly on the camera’s web interface:
          • Video Codec: H.264 (Strict Baseline/Main profile, Zipstream completely disabled).
          • Resolution: Adjusted to 640x360 (16:9 widescreen profile matching the Monocle portal configuration).
          • Frame Rate: Hard-capped at a stable 15 FPS.
          • Audio: Completely disabled/stripped from the stream to prevent Alexa from dropping the connection due to unsupported audio codecs.
          • Monocle Tags: Switched from @tunnel to @proxy to bypass the deprecated tunneling service.

          4. The Remaining Bottleneck:
          With the custom properties active, the gateway starts flawlessly, binds to port 443 (LISTENING confirmed via admin netstat), and successfully registers the camera stream directly with a 200 (OK) response from the Axis camera.
          However, despite clearing all local firewalls, ensuring the Echo Show 8 is on the main private Wi-Fi network, and forcing a full Alexa Smart Home device rediscovery, the gateway logs still show absolutely zero inbound connection lines when requesting the stream via the Echo Show 8. The window remains completely stagnant at the registration handshake.

          Current Targeted Questions based on this state:
          • Given that the gateway claims it expects inbound traffic via rtsp://[unique-id].mproxy.io:443/STREAM:[stream-id], is it verified that the Amazon Alexa Cloud infrastructure still considers the *.mproxy.io SSL/TLS root certificates valid, or are Echo devices silently dropping the connection due to expired or untrusted gateway certificates?
          • Why does the Windows gateway log show that it successfully registers @proxy, but completely ignores the custom rtsp.register.host=192.168.1.5 setting in the log printout, still insisting on printing the public mproxy.io URL instead of the local IP fallback?
          Any guidance on why the Echo Show 8 completely fails to hit the open port 443 on the host PC despite a clean local handshake would be highly appreciated.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Privacy Policy  |  Terms & Conditions

          © 2018 shadeBlue, LLC.