Improving Dahua Camera Security

cdre

n3wb
Dec 27, 2017
4
1
Hi, I've been running a few Dahua bullet cams and and just added a few more turret and PTZ versions. Very happy with them and primarily use them with my Milestone server.

I've heard these cameras "phone home" so I want to control external comms a little. At the router level, I'd like to blacklist all ports not used for the purpose of email notifications. I'm using gmail which works at port 587. I blacklisted all ports other than 25 and 587 but am getting email test failures at that setup. Success when not blacklisting, so there is a port dependency I'm not aware of.

Any recommendations on getting this working or otherwise securing my cameras better? Obviously firmware updates and password are table stakes. I would deny them access to the gateway server and view exclusively through Milestone but want to get email working if I can... Already killed port forwarding to my server and viewing remotely only through a VPN.
 
Turn Upnp off on the router and cameras. Give the cameras a 1.0.0.1 dns and just use your vms to get e-mails. Not sure if you can use milestone for that purpose. With blue iris you can setup emails thru the vms.
 
Thanks Bubba. Unfortunately Milestone's free server doesn't allow email alerts (as far as I know). Otherwise it's super capable....
 
I assume you saw the “Dahua camera best practices“ post linked and summarized in my cliff notes post? It sounds like you have a handle on this, but you may see something useful in there. See the link in my signature.


Sent from my iPhone using Tapatalk