Legato Projector

Legato projector

An NEC NP-V300W (serial 2500210EE, LAN firmware 1.00.009), fed by the SVSi decoder named Legato Projector (10.0.25.133). The decoder carries its HDMI and RS-232, and its network cable runs into the decoder’s second Ethernet jack, so it shares Atrium switch port 0/16 on the AVoIP VLAN.

   
Address 10.0.25.134/24, static, gateway 10.0.25.254
MAC 00:25:5c:cb:01:b7 (router reservation AVoIP-LEGATO-PROJECTOR)
Control TCP 7142, NEC’s binary projector protocol
Web UI http://10.0.25.134/ — network settings only, no login
RS-232 via the decoder, 38400 8N1 — what AMX uses

The Atrium projector is a different unit, a Panasonic PT-EZ590 behind the Atrium Projector decoder (.126). See Atrium projector.

Controlling it

AMX drives it through the decoder: sendser: projector_on / projector_off / projector_input_hdmi on UDP 50001 replays serial codes stored on the decoder’s Serial page (Automation/amx/include/Legato.axi).

Over the network, Automation/server/scripts/nec-projector.py speaks the same protocol on TCP 7142. The AVoIP VLAN is only reachable from docker-server; run from anywhere else, the script tunnels through it with ssh -W.

nec-projector.py status
nec-projector.py power on|off
nec-projector.py input hdmi|computer1|computer2|video|svideo
nec-projector.py mute picture|sound|onscreen on|off
nec-projector.py freeze on|off
nec-projector.py raw 00 BF 00 00 01 02

status reads power state, what’s showing, input, mute and freeze state, error flags, lamp hours and remaining lamp life, and eco mode.

Commands tested against this projector (the last byte of each is a checksum, the low byte of the sum of the others; nec-projector.py adds it):

Command Bytes Result
305-3 basic information 00 BF 00 00 01 02 power, content, input, mutes, freeze ✅
305-1 model / 305-2 serial 00 BF 00 00 01 00 / 00 BF 00 00 02 01 06 V300W / 2500210EE ✅
009 error status 00 88 00 00 00 ✅
037-4 lamp usage / life 03 96 00 00 02 00 01 / …00 04 seconds / percent ✅
097-8 eco mode 03 B0 00 00 01 07 ✅
015 power on 02 00 00 00 00 from standby to video in 65–95 s ✅
016 power off 02 01 00 00 00 ✅, but refused for a while after power on — see below
018 input 02 03 00 00 02 01 <input> 1A HDMI, 01 COMPUTER1, 02 COMPUTER2, 06 VIDEO, 0B S-VIDEO ✅
020/021 picture mute on/off 02 10 … / 02 11 … ✅
022/023 sound mute on/off 02 12 … / 02 13 … ✅
024/025 onscreen mute on/off 02 14 … / 02 15 … ✅
079 freeze on/off 01 98 00 00 01 01 / …02 ✅
078-4 mute status 00 85 00 00 01 03 answers, but always reads unmuted ❌ — use 305-3

030-2 VOLUME ADJUST answers (a relative change of 0 was accepted) but a real level change hasn’t been tried. NEC’s command reference and the per-model appendix are the Projector Control Command Reference Manual and its Appendixes.

There’s no PJLink (TCP 4352 is closed). The web UI’s Crestron RoomView option is off.

Power

Both power commands work over the LAN and through the decoder’s RS-232 (AMX’s projector_on took it from standby to video in 94 s).

  • Power on takes 65–95 s to show video. Status reads 01h for most of that and 02h for the last ten seconds or so; neither is in NEC’s table.
  • Power off cools for about 8 s, then reads standby (sleep). The LAN stays up in standby: it answers ping and TCP 7142.
  • Power off is refused for a while after power on, with error 02h 0Dh (“power is off”). Once that lasted about a minute after video appeared; other times it was still refused several minutes later. nec-projector.py power off retries every 10 s until it’s accepted. AMX’s projector_off through the decoder gets no reply, so one sent in that window is silently lost.

Power on over the LAN depends on the menu’s Standby Mode: NEC’s appendix says the V300W only accepts it in NORMAL, and in POWER-SAVING the LAN is off in standby. This one is in NORMAL.

Quirks

  • It ignores ARP from other subnets. A sweep from any address outside its own subnet gets nothing back, and since it never transmits unprompted, no switch learns its MAC either. That’s how it sat on the factory default 192.168.0.10 unnoticed. arp-scan --arpspa=<an address in its subnet> finds a device like this.
  • It keeps ARP entries and doesn’t re-ARP. If the MAC behind an address changes — a new container, say — it keeps replying to the old one. Reach it from a stable address.
  • Its TCP stack holds only a few connections. A half-open one (a SYN whose SYN-ACK went nowhere) blocks new connections, which are reset, until it times out after a minute or two. Open one connection, send, and close cleanly. A connection opened straight after the last one closed is refused; 0.1 s later it’s accepted. Several commands on one connection work.
  • An input change within about 3 s of the previous one is acknowledged and ignored. 4 s or more worked every time. Leave 5 s and confirm with status.
  • The decoder doesn’t capture the projector’s replies. Commands sent through it arrive (picture mute from its Serial page takes effect), but its Serial page reads No data for every query. That is why status comes over the LAN.
  • A state read straight after a command can still show the old value; give it a second.