Security & Privacy Concern: Vigi App does not work over LAN

Security & Privacy Concern: Vigi App does not work over LAN

Security & Privacy Concern: Vigi App does not work over LAN
Security & Privacy Concern: Vigi App does not work over LAN
Tuesday - last edited Yesterday
Model: VIGI NVR4032H  
Hardware Version:
Firmware Version:

I am trying to harden my network by blocking both inbound and outbound internet access for my CCTV VLAN. My goal is to access the system only while on-site or through a self-managed VPN.
 

When I apply this restriction, the NVR web interface continues to work correctly, but the Android app stops working. This happens even when the phone is connected to a WiFi access point that is on the same CCTV VLAN.
 

Based on this setup, the app should work purely over the local network as long as LAN access is permitted. Requiring internet connectivity in this scenario feels unnecessary and raises a security concern, since the system appears to depend on external connectivity even when local access should be sufficient.
 

To confirm there is no connectivity issue within the LAN, I can access the NVR web interface from the phone browser without any problem. This shows the phone can reach the NVR directly on the VLAN.
 

Is there a way to make the Android app operate fully in local-only mode without requiring internet access?

  0      
  0      
#1
Options
2 Reply
Re:Vigi App does not work over LAN
Yesterday

  @PriyankP Can you remove and re-add the device to your app by scanning the QR code on the NVR itself? If doing this while your phone is on the same LAN as the NVR, you should be able to add the NVR to your devices and view it locally instead of over the internet. 

  0  
  0  
#2
Options
Re:Vigi App does not work over LAN
Yesterday

@NeilR_M I tested the suggested steps and here are the results.
 

Scenario 1
Phone connected to the CCTV VLAN via WiFi. Cellular data OFF.

I cannot add the device by scanning the QR code. The app reports that the device is not connected to the internet.
The NVR does appear in the auto-discovery list, which confirms the phone can see it on the local network, but adding it still fails with the same "no internet" error.
 

Scenario 2
Phone connected to the CCTV VLAN via WiFi. Cellular data ON.

In this case the app allows me to add the NVR. It shows recording thumbnails, but playback does not work and live view does not start.

My expectation is that internet access should not be required in either scenario. If the app can discover the NVR locally or if I provide the local IP address, the connection should remain entirely within the LAN. Requiring an internet lookup in this situation does not seem necessary.
 

Internet access might make sense when adding a device using a serial number or QR code as ID to IP lookup table may be hosted in the cloud. However, when the device is clearly discoverable and reachable on the local network, the dependency on internet connectivity becomes a significant security and privacy concern.

  1  
  1  
#3
Options