how to separate out IP cameras but still get access to the NVR?

Jan 27, 2018
3
0
Im having some trouble with my IP camera setup and not sure about best practices / what i should do?

I currently have:
Home network on 192.168.1.0/24 being routed using EdgeRouterPro (connected to WAN)
a dedicated m4100-26g-poe netgear switch (l2/l3) to connect the Ip cameras and NVR to.

I would ideally like:
1) the IP cameras to be separated from my home network and non wan facing.
2) the NVR to be able to access both the cameras and my home network.(it only have 1 NIC).

I have tried creating a VLAN specifically for my cameras on ports 5-10 on the switch and NVR on the home network on Port 2. The problem i am having is i cannot seem to get the NVR to access both the cameras and the homenetwork at the same time?

How should i setup this part of the network. The aim is to keep all the IP camera traffic on the m4100 switch and keep is secure.
 
What is your NVR? A PC? Brand?

To do what you are trying to do you'd need to have two LAN ports on your NVR so that you could have one port connected to the switch LAN dedicated to the cameras and the other to the LAN which is Internet facing. You could of course do this virtualized but that would not be the recommended approach for a dedicated NVR.

If you only have one LAN port on the NVR then it can only be on one physical network.

Of course you could VLAN the two ports on the NVR through your physical switch but you'd still need two ports to do so.
 
What is your NVR? A PC? Brand?

To do what you are trying to do you'd need to have two LAN ports on your NVR so that you could have one port connected to the switch LAN dedicated to the cameras and the other to the LAN which is Internet facing. You could of course do this virtualized but that would not be the recommended approach for a dedicated NVR.

If you only have one LAN port on the NVR then it can only be on one physical network.

Of course you could VLAN the two ports on the NVR through your physical switch but you'd still need two ports to do so.

Sorry I should have been more clear. It is a hikvision 7716ni-i4-16p. It only has 1 NIC, but also an inbuilt 16p poe. How else can I do what I am trying to do? Ie keep the cameras away from my internet but let the NVR see both (internet and cameras). Can I utilise something on the l2/l3 switch?