General camera and system security

Jim W

Young grasshopper
Joined
Sep 19, 2014
Messages
73
Reaction score
2
I have a about 9 cameras covering several buildings and due to the distances involved about 200 metres from the main internet router I have about 8 Linksys WAG320N set to bridge mode. These routers act as wireless access points and have a USB port that you plug in a hard drive for recording video.
I'm no internet security expert so can anyone give me some pointers on the best way to prevent unauthorised access and hacking ?
 

aristobrat

IPCT Contributor
Joined
Dec 5, 2016
Messages
2,983
Reaction score
3,180
One of the bigger things is to make sure you are not port-forwarding the cameras directly to the Internet (or allow the cameras to use uPNP to forward ports on their own, which is an option in some cameras that comes enabled by default).
 

Jim W

Young grasshopper
Joined
Sep 19, 2014
Messages
73
Reaction score
2
One of the bigger things is to make sure you are not port-forwarding the cameras directly to the Internet (or allow the cameras to use uPNP to forward ports on their own, which is an option in some cameras that comes enabled by default).
Yes I figured the port forwarding was an issue but is there any other way to view the cameras whilst away ? I looked into the VPN thing but not got my head around it yet
 

aristobrat

IPCT Contributor
Joined
Dec 5, 2016
Messages
2,983
Reaction score
3,180
VPN is the way to go. All you need to set this up is a device on your end that can run the VPN server. What brand/model is your main Internet router, and do you have the ability to swap it out for a different model (if you wanted to)?
 

Jim W

Young grasshopper
Joined
Sep 19, 2014
Messages
73
Reaction score
2
VPN is the way to go. All you need to set this up is a device on your end that can run the VPN server. What brand/model is your main Internet router, and do you have the ability to swap it out for a different model (if you wanted to)?
It's an older Linksys which I'm thinking about changing to a better one which works with OpenVPN but not sure whether they work with phone line DSL
 

randytsuch

Pulling my weight
Joined
Oct 1, 2016
Messages
495
Reaction score
176
If your linksys works with your DSL modem, I'd expect any decent newer router to work with it too.
I have a asus router that handles OpenVPN with no problem. Its now an slightly older model, but works well for me.
 

Jim W

Young grasshopper
Joined
Sep 19, 2014
Messages
73
Reaction score
2
I looked at the ASUS router which seems the only one that you can run the OpenVPN software others require 3rd party firmware which I can't be bothered with.My main router acts as the DHCP server all the others are set to bridge mode and once in bridgemode lot's of featues are unavailable so I need this ASUS to work with the DSL internet rather than the cable variety which has me confused as to the correct model to buy

Update I checked out the
ASUS DSL-AC68U and I think it will work OK
 
Last edited:

aristobrat

IPCT Contributor
Joined
Dec 5, 2016
Messages
2,983
Reaction score
3,180
If you don't mind another box on your network, you can get an inexpensive Raspberry Pi and run OpenVPN on that, leaving your current router in place.

I didn't get a chance to watch 100% of this video, but it does a good job of explaining the gist of the process:
 

Jim W

Young grasshopper
Joined
Sep 19, 2014
Messages
73
Reaction score
2
I gotta avoid extra complications around here but I watched the video along with lots of other tutorial youtube vids.
I'll upgrade my main house router to the Asus and add a large capacity USB harddrive too it. The feature I like about the Hikvision cameras is the ability to record/retain a few seconds of video prior to a motion or intrusion event and I also tend to use the email image facility. I rarely want to view cameras while I'm offsite
 

mycatjest

Young grasshopper
Joined
Nov 26, 2017
Messages
56
Reaction score
16
hi

before you buy the asus , make sure u get a model that supports the "merlin firmware" - its well known , used and fully maintained firmware i have been running it for about 5 yrs now, its better than the asus firmware

suspect you may want to go with the one of the top models if u use VPN - its the only reason im swithing as the AC86U is dual core and will max out my FTCC line for vpn, eg it blows anything at this price out of the water for performance...

the small net builder forum is where u will find a large following and home of merlin

ttps://www.snbforums.com/forums/asuswrt-merlin.42/

some stats on routers and vpn performnace

asus AC3100 (1.4 Ghz dual core)
CTF (Cut Through Forwarding NAT Acceleration)
DL: 61 Mbps with core 1 at 25%, core 2 at 75%
DL :74 Mbps with core 1 at 30%, core 2 at 85% with mods*
UL: 84 Mbps with core 1 at 35%, core 2 at 100%

asus AC68U (1.0 Ghz dual core)
CTF enabled
DL: 44 Mbps with core 1 at 30%, core 2 at 80%
UL: 58 Mbps with core 1 at 40%, core 2 at 100%


asus AC86U (1.8 Ghz dual core) (tested 12/20/17)
Flow Cache enabled
DL: 223 Mbps with core 1 at 35%, core 2 at 70%
UL: 233 Mbps with core 1 at 55%, core 2 at 90%


Data encryption: AES-128-CBC
Data authentication: SHA1
Handshake: RSA-2048

*Adding the following lines to the custom configuration bumped the DL speeds to 74 Mbps.
sndbuf 524288
rcvbuf 524288
push "sndbuf 524288"
push "rcvbuf 524288"

I also got a little speed increase by adding:
fast-io
 

aristobrat

IPCT Contributor
Joined
Dec 5, 2016
Messages
2,983
Reaction score
3,180
@Jim W, no problem. The Raspberry Pi is just an inexpensive box that you can build and then plug into your router that would let you get OpenVPN capabilities without having to upgrade the router. Just through it out there in case you didn't want to have to upgrade your router.
 

mycatjest

Young grasshopper
Joined
Nov 26, 2017
Messages
56
Reaction score
16
just saw u had dsl .. ask on the merlin forum - they will be able to advise on how to use / what to buy given your line speed
 

Jim W

Young grasshopper
Joined
Sep 19, 2014
Messages
73
Reaction score
2
Apparently Merlin won't work with any DSL router
 

Jim W

Young grasshopper
Joined
Sep 19, 2014
Messages
73
Reaction score
2
I bought a used ASUS router
Is there a way to only allow access to the cameras or router from a specific device using the MAC address ?
 
Top