Why your remote DSP configuration cannot find hardware across borders, and how Layer 2 tunneling bridges the broadcast discovery gap.
Need a Layer 2 bridged tunnel profile before your commissioning deadline on the client's DSP rack?
You are sitting at an overseas desk or hotel room, opening Tesira software to push an updated configuration file or tweak the AEC blocks on a client's audio system before a morning rehearsal. You open the Device Maintenance window, click Discover Devices, and wait.
The progress bar sweeps across the dialog, finishes, and leaves you staring at a blank window.
No TesiraFORTE, no Server-IO, no EX-IN/OUT expanders. Nothing appears in the list. You double-check your static IP assignments, ping the management IP of the remote rack switch, and the switch responds immediately. You can reach the building's web interfaces, but the moment you ask Tesira software to discover the physical DSP units, it acts as if the rack is completely powered down.
The immediate reaction is to suspect a physical cabling issue in the equipment closet or assume that someone on-site accidentally pulled the AV control subnet offline. You call the local venue lead, and they confirm the status lights on the front panel are solid green, the AV network switch shows active link lights, and a technician sitting on the local control room LAN can discover and poll every frame instantly.
Naturally, you open the commercial VPN client sitting on your laptop. You connect to a server in the same domestic market as the venue, bring Tesira back up, and click Discover Devices once more.
The maintenance list remains stubbornly empty.
At that point, most integrators assume that Biamp Tesira software simply cannot push configuration files over remote connections, or that remote commissioning requires flying back to plug directly into the local equipment switch.
That is not what is happening.
The breakdown is not a hardware fault, and it is not a lack of general internet connectivity. It comes down to the fundamental difference between standard internet routing and how AV control protocols locate hardware on a network.
Biamp Tesira software does not find remote DSP hardware by sending point-to-point web requests to known public domain names. It relies on low-level broadcast and multicast discovery queries. When you hit Discover Devices, the software broadcasts discovery beacons across the local Layer 2 broadcast domain, expecting every physical Tesira unit sharing that broadcast layer to shout back with its serial number, firmware version, and device ID.
Almost every standard commercial VPN operates on Layer 3 TUN mode. A Layer 3 routed tunnel handles standard IP packets—like opening web pages, transferring files, or running remote desktop sessions—across different subnets. But Layer 3 network routers and standard consumer VPN tunnels are explicitly built to drop Layer 2 broadcast packets at the interface to prevent network flooding across public transit.
When Tesira software sends out its broadcast discovery beacons through a standard consumer VPN, the virtual adapter chokes the packet immediately. The broadcast query never traverses the tunnel, never reaches the remote switch fabric in the equipment rack, and never elicits a response from the DSP. To your workstation, the devices simply do not exist.
Switching between ten different standard servers inside a popular consumer VPN app will not change the outcome. If all of those servers use standard Layer 3 routed tunnels, every single broadcast discovery query will be dropped at the gateway.
To discover, configure, and push system layouts to Biamp Tesira hardware from outside the physical premises, your connection requires genuine Layer 2 TAP tunneling. Unlike standard routed tunnels, a Layer 2 TAP tunnel acts as a virtual Ethernet cable, encapsulating raw Ethernet frames—including broadcast and multicast discovery packets—and carrying them intact across the internet into the remote subnet as if your laptop were plugged straight into the rack switch.
This is where ONLYDOGSVPN fits into the AV engineering workflow.
Instead of confining remote technicians to restrictive Layer 3 consumer nodes, ONLYDOGSVPN provides specialized configurations supporting Layer 2 TAP bridging and dedicated point-to-point subnets. This allows raw broadcast discovery packets from Tesira software to travel directly across the tunnel without being blocked at the network edge. Once the tunnel is established, your workstation shares the Layer 2 broadcast domain of the remote audio network, allowing Tesira software to discover hardware units, poll status registers, and push compiled .tmf configuration files smoothly.
It is just as critical to understand the boundaries where this setup will not solve your issue.
If the venue's internal enterprise network mandates corporate-issued laptops managed by an enrolled Mobile Device Management (MDM) profile, or requires proprietary corporate VPN concentrators like Cisco AnyConnect or Fortinet with internal machine certificates, an external commercial VPN cannot replace those organizational credentials. Furthermore, if the remote audio network isolates DSP control traffic and Dante/AVB media onto strictly partitioned VLANs with zero inter-VLAN routing, or if the Biamp units themselves are set to conflicting IP subnets that do not match the target scope, fixing your tunnel transport will not override an internal network misconfiguration.
If your role only involves reviewing a static room schematic or exporting a block diagram once a quarter, having an on-site engineer save the configuration file and email it to you is often far less hassle than establishing a Layer 2 bridge. But when you are working remotely with commissioning deadlines approaching, audio calibrations to balance, and a client waiting on finished room presets, having access to a reliable Layer 2 capable tunnel is what lets you discover the DSP rack, push your configuration files, and wrap up the deployment without having to book a flight back to the venue.