Skip to content

Networking

abbas0444 edited this page Sep 9, 2026 · 1 revision

Server and device on different networks

The connection goes from your server to the device, over TCP. So the server has to be able to reach the machine — not the other way round.

That is fine when both sit in the same office. It is not fine when ERPNext runs on a cloud server: nothing on the internet can reach 192.168.1.201, because that address means something different on every network in the world. The log then shows:

[PROBLEM] Could not reach front-door at 192.168.1.201:4370 from this server - timed out

Pick one of the three ways round it.

A. Port forwarding

Simplest, and permanent.

On the office router, forward TCP port 4370 to the device's LAN address. Then put the office's public IP in Device IP Address.

For a second machine, forward a different outside port — 4371, say — to that machine's port 4370, and put 4371 in the device row's Port field.

Device Name Device IP Address Port Router forwards
front-door 203.0.113.7 4370 4370 → 192.168.1.201:4370
back-gate 203.0.113.7 4371 4371 → 192.168.1.202:4370

A word of warning. ZK devices have almost no authentication. Forwarding one to the open internet means anyone who finds it can read your attendance log and, on some firmware, more than that. If your router allows it, restrict the forward to your server's IP address. If it does not, prefer option C.

B. SSH reverse tunnel

Good when you cannot touch the router, and you have an office PC that can reach both the device and the server.

ssh -N -R 4370:192.168.1.201:4370 user@your-server

While that runs, the server reaches the device on 127.0.0.1, so set Device IP Address to 127.0.0.1.

For a second machine, add another mapping on a different local port:

ssh -N -R 4370:192.168.1.201:4370 -R 4371:192.168.1.202:4370 user@your-server

and give the second row Port 4371.

Run it through autossh, or as a systemd service, so it comes back after a reboot. Otherwise attendance stops the first time that PC restarts.

C. VPN

The most secure, and the least fiddly once it is up. WireGuard or OpenVPN between the server and the office router. The devices keep their LAN addresses and nothing is exposed to the internet.

Checking it works

From the server:

nc -vz 203.0.113.7 4370

If that does not connect, the app will not either — fix the network first. Once it connects, press Sync Attendance Now.

Clone this wiki locally