Legato Projector
Legato projector
An NEC NP-V300W (serial 2500210EE, LAN firmware 1.00.009), fed by the SVSi decoder named
Legato Projector (10.0.25.133). The decoder carries its HDMI and RS-232, and its network cable
runs into the decoder’s second Ethernet jack, so it shares Atrium switch port 0/16 on the AVoIP
VLAN.
| Address | 10.0.25.134/24, static, gateway 10.0.25.254 |
| MAC | 00:25:5c:cb:01:b7 (router reservation AVoIP-LEGATO-PROJECTOR) |
| Control | TCP 7142, NEC’s binary projector protocol |
| Web UI | http://10.0.25.134/ — network settings only, no login |
| RS-232 | via the decoder, 38400 8N1 — what AMX uses |
The Atrium projector is a different unit, a Panasonic PT-EZ590 behind the Atrium Projector
decoder (.126). See Atrium projector.
Controlling it
AMX drives it through the decoder: sendser: projector_on / projector_off /
projector_input_hdmi on UDP 50001 replays serial codes stored on the decoder’s Serial page
(Automation/amx/include/Legato.axi).
Over the network, Automation/server/scripts/nec-projector.py speaks the same protocol on TCP 7142.
The AVoIP VLAN is only reachable from docker-server; run from anywhere else, the script tunnels
through it with ssh -W.
nec-projector.py status
nec-projector.py power on|off
nec-projector.py input hdmi|computer1|computer2|video|svideo
nec-projector.py mute picture|sound|onscreen on|off
nec-projector.py freeze on|off
nec-projector.py raw 00 BF 00 00 01 02
status reads power state, what’s showing, input, mute and freeze state, error flags, lamp hours
and remaining lamp life, and eco mode.
Commands tested against this projector (the last byte of each is a checksum, the low byte of the
sum of the others; nec-projector.py adds it):
| Command | Bytes | Result |
|---|---|---|
| 305-3 basic information | 00 BF 00 00 01 02 |
power, content, input, mutes, freeze ✅ |
| 305-1 model / 305-2 serial | 00 BF 00 00 01 00 / 00 BF 00 00 02 01 06 |
V300W / 2500210EE ✅ |
| 009 error status | 00 88 00 00 00 |
✅ |
| 037-4 lamp usage / life | 03 96 00 00 02 00 01 / …00 04 |
seconds / percent ✅ |
| 097-8 eco mode | 03 B0 00 00 01 07 |
✅ |
| 015 power on | 02 00 00 00 00 |
from standby to video in 65–95 s ✅ |
| 016 power off | 02 01 00 00 00 |
✅, but refused for a while after power on — see below |
| 018 input | 02 03 00 00 02 01 <input> |
1A HDMI, 01 COMPUTER1, 02 COMPUTER2, 06 VIDEO, 0B S-VIDEO ✅ |
| 020/021 picture mute on/off | 02 10 … / 02 11 … |
✅ |
| 022/023 sound mute on/off | 02 12 … / 02 13 … |
✅ |
| 024/025 onscreen mute on/off | 02 14 … / 02 15 … |
✅ |
| 079 freeze on/off | 01 98 00 00 01 01 / …02 |
✅ |
| 078-4 mute status | 00 85 00 00 01 03 |
answers, but always reads unmuted ❌ — use 305-3 |
030-2 VOLUME ADJUST answers (a relative change of 0 was accepted) but a real level change hasn’t
been tried. NEC’s command reference and the per-model appendix are the
Projector Control Command Reference Manual
and its
Appendixes.
There’s no PJLink (TCP 4352 is closed). The web UI’s Crestron RoomView option is off.
Power
Both power commands work over the LAN and through the decoder’s RS-232 (AMX’s projector_on took
it from standby to video in 94 s).
- Power on takes 65–95 s to show video. Status reads
01hfor most of that and02hfor the last ten seconds or so; neither is in NEC’s table. - Power off cools for about 8 s, then reads standby (sleep). The LAN stays up in standby: it answers ping and TCP 7142.
- Power off is refused for a while after power on, with error
02h 0Dh(“power is off”). Once that lasted about a minute after video appeared; other times it was still refused several minutes later.nec-projector.py power offretries every 10 s until it’s accepted. AMX’sprojector_offthrough the decoder gets no reply, so one sent in that window is silently lost.
Power on over the LAN depends on the menu’s Standby Mode: NEC’s appendix says the V300W only accepts it in NORMAL, and in POWER-SAVING the LAN is off in standby. This one is in NORMAL.
Quirks
- It ignores ARP from other subnets. A sweep from any address outside its own subnet gets
nothing back, and since it never transmits unprompted, no switch learns its MAC either. That’s
how it sat on the factory default
192.168.0.10unnoticed.arp-scan --arpspa=<an address in its subnet>finds a device like this. - It keeps ARP entries and doesn’t re-ARP. If the MAC behind an address changes — a new container, say — it keeps replying to the old one. Reach it from a stable address.
- Its TCP stack holds only a few connections. A half-open one (a SYN whose SYN-ACK went nowhere) blocks new connections, which are reset, until it times out after a minute or two. Open one connection, send, and close cleanly. A connection opened straight after the last one closed is refused; 0.1 s later it’s accepted. Several commands on one connection work.
- An input change within about 3 s of the previous one is acknowledged and ignored. 4 s or more
worked every time. Leave 5 s and confirm with
status. - The decoder doesn’t capture the projector’s replies. Commands sent through it arrive (picture
mute from its Serial page takes effect), but its Serial page reads
No datafor every query. That is why status comes over the LAN. - A state read straight after a command can still show the old value; give it a second.