Anybody looking at your LOG files?

A K

n3wb
Joined
Oct 4, 2015
Messages
24
Reaction score
0
Seems like I am getting all different server logons on my BI except my mobile app. I traced these strange IP addresses to China and Poland. What gives? It seems everybody and my brother can get to my server from outside my LAN but I can't connect to it. Mobile app don't work for me. I'm trying to use Stunnel and HTTPS.
 

fenderman

Staff member
Joined
Mar 9, 2014
Messages
36,905
Reaction score
21,279
Seems like I am getting all different server logons on my BI except my mobile app. I traced these strange IP addresses to China and Poland. What gives? It seems everybody and my brother can get to my server from outside my LAN but I can't connect to it. Mobile app don't work for me. I'm trying to use Stunnel and HTTPS.
logons or attempted logins? If you cannot remotely connect its likely the result of improper setup. You may have actually made it easier for someone to gain access. Setup a vpn if you are concerned.
 

A K

n3wb
Joined
Oct 4, 2015
Messages
24
Reaction score
0
I think it was attempted. no log out. I can log in with my android while I am on the lan and finally connected on the wan but my battery backup crapped out and modem and it reset with different IP and can't get it set back up. BI works great as a server with recordings and monitoring but it's a night mare for me on mobile. I finally got it to work remotely but all I had was color bars for picture. Been playing with this for months. finally found that the NAT workaround got me connected off my lan but yesterday's reset screwed me up.
 

fenderman

Staff member
Joined
Mar 9, 2014
Messages
36,905
Reaction score
21,279
I think it was attempted. no log out. I can log in with my android while I am on the lan and finally connected on the wan but my battery backup crapped out and modem and it reset with different IP and can't get it set back up. BI works great as a server with recordings and monitoring but it's a night mare for me on mobile. I finally got it to work remotely but all I had was color bars for picture. Been playing with this for months. finally found that the NAT workaround got me connected off my lan but yesterday's reset screwed me up.
Blue iris works perfectly remotely. Its a setup issue on your end. You should be using a dynamic dns service or blue iris built in option. That is basic portforwarding/networking.
 

A K

n3wb
Joined
Oct 4, 2015
Messages
24
Reaction score
0
Any suggestions on which VPN is best? As for port forwarding, my wireless router is set up for UPNing but doesn't work. Linksys 3200. Could the DLink software screw me up any? I have DLink lite on my android and it works. Only thing was when I typed in my IP address from remote computer it came up with one of my cameras
 

fenderman

Staff member
Joined
Mar 9, 2014
Messages
36,905
Reaction score
21,279
Any suggestions on which VPN is best? As for port forwarding, my wireless router is set up for UPNing but doesn't work. Linksys 3200. Could the DLink software screw me up any? I have DLink lite on my android and it works. Only thing was when I typed in my IP address from remote computer it came up with one of my cameras
upnp opens a bunch of ports which creates a security risk. You should not be port forwarding individual cameras. There are several threads discussing vpn. You dont want a service that masks your own ip. Look search the forum for openvpn.
 

bp2008

Staff member
Joined
Mar 10, 2014
Messages
12,680
Reaction score
14,041
Location
USA
If UPnP is on in your router, turn it OFF. With UPnP enabled, IP cameras reach out to your router and open ports to themselves, which is a terrible plan because 1) you don't know it is happening, 2) you don't know which ports are being opened, 3) most IP cameras are insecure as all hell so once they are open to the world like this, their vulnerabilities are easily exploited and an attacker has full access to the camera video or even your entire home network.

OpenVPN is one of the more secure options, but most routers don't have a server for this straight out of the box, and most devices don't have a built-in client (you'd need to download it). The simplest option is PPTP vpn, which your router may support already, and every modern computer or smart phone can connect to.
 

Q™

IPCT Contributor
Joined
Feb 16, 2015
Messages
4,990
Reaction score
3,991
Location
Megatroplis, USA
Bad guys attack standard known ports. My RDP server at the office was absorbing thousands of bad logon attempts until I changed RDP port from the standard 3389 to 40789 and in the ensuing year I've had zero bad guy traffic. It's hard to believe that such a simple solution could have such an effective result. You may want to change the port which your BI server listens on to something within the 49152–65535 range. Just an idea.
 

A K

n3wb
Joined
Oct 4, 2015
Messages
24
Reaction score
0
I have the DLink program running on same server as BI. Half the time I can't get BI up so I fell back to D Link.
 

fenderman

Staff member
Joined
Mar 9, 2014
Messages
36,905
Reaction score
21,279
I have the DLink program running on same server as BI. Half the time I can't get BI up so I fell back to D Link.
Then you need to figure out what you are doing wrong.
 

A K

n3wb
Joined
Oct 4, 2015
Messages
24
Reaction score
0
i think it's all in the router. Might go back to old one or use dedicated one just for cameras.
 

A K

n3wb
Joined
Oct 4, 2015
Messages
24
Reaction score
0
I wish were my neighbor . I could keep your HVAC running and I'd trade for you keeping my cameras running HA
 
Top