I have a DVR system setup on my network. I access it using a VPN and port forwarding has been disabled. I also blocked the camera itself from the internet using an iptable firewall rule. I confirmed that the camera was inaccessible through port forwarding when I had this rule setup, so I believe the camera doesn't have access to the internet and is only accessible from within the network. Before I implemented this rule, I was able to access my DVR online using port forwarding, when I had it enabled for testing purposes. I do not have any VLANs setup so all of my devices are essentially able to communicate with each other. I'm using a Raspberry Pi as a VPN.
I wanted to know if I should consider setting up isolated VLANs on my network. How much of a security risk is it for me to not have VLANs even if the DVR itself is blocked from accessing the internet?
I'm not a networking expert so I don't have a lot of understanding of how to setup VLANs, but I think I'm capable of figuring it out. The reason why I haven't embarked on that is because my router doesn't seem to have VLAN capabilities through its DD-WRT interface. I might be able to set it up using SSH, but that would make things even more complicated and I wanted to know if it would be worth the time or see if anyone can suggest a guide or some advice before I started doing some serious research.
I wanted to know if I should consider setting up isolated VLANs on my network. How much of a security risk is it for me to not have VLANs even if the DVR itself is blocked from accessing the internet?
I'm not a networking expert so I don't have a lot of understanding of how to setup VLANs, but I think I'm capable of figuring it out. The reason why I haven't embarked on that is because my router doesn't seem to have VLAN capabilities through its DD-WRT interface. I might be able to set it up using SSH, but that would make things even more complicated and I wanted to know if it would be worth the time or see if anyone can suggest a guide or some advice before I started doing some serious research.