HTTPS and Port 81

Ian Robert

n3wb
Joined
May 15, 2018
Messages
6
Reaction score
0
Location
Whyalla, Australia
I recently purchased license and installed the app and set
up my cameras.

First I had HTTP port 81 web access and used the built in wizard
to set it up. BI Wizard I think opened port 81 on my router.

Now I have stunnel (www.stunnel.org) installed. I opened port 443 in router port
forwarding to the machine running BI where I have Stunnel running too. In Stunnel I set port 443 to be routed to blue iris to port 81. I enabled HTTPS in Blue iris. I can access BI via port 443 https connection externally.

However I can see my port 81 is still opened. Then I closed HTTP
connection in Blue Iris and once done nothing work as Stunnel use port
81 to route the traffic I belive. However when I enable HTTP the Blue iris
again as open port 81 in the router get opened by BI anyone can now come via port 81 to
the network and access blue iris directly bypassing Stunnel. This defeat the
purpose.

Can I just have port 443 open in the router for web traffic and have port 81 for intenal traffic (LAN). That is to have port 81 open in machine running BI and not the
router. I do not want people to use port 81 to get in to BI. My question is how to do this and how to prevent BI opening the router port. I cannot disable it in the router.

It is BI that open the port 81 and nothing else. When I un-tick HTTP
in BI the port 81 of the router get closed as I confirmed with
Open Port Check Tool - Test Port Forwarding on Your Router

This defeat the purpose

I am sure this is not just a problem for me

Please advise a solution
 

Terk

Pulling my weight
Joined
Feb 14, 2018
Messages
247
Reaction score
106
Make sure you have the client using https for external and internal connections and all you should need open on the router is port 443 if that is what your sTunnel is listening on. However you should really consider closing all port forwarders and using OpenVPN on your mobile device to connect to your router where the VPN server would need to be configured if your router has that option or upgrade your router to an ASUS model if it doesn't it will be much more secure than even an https open port. Also make sure UPNP is disabled on your router.
 
Top