Question about lan when using 3 gateways?

Jared

Young grasshopper
Joined
Apr 3, 2017
Messages
66
Reaction score
8
I want to restrict users to lan only access but my lan consists of 3 gateways.

computer gateway 192.168.1.1 and Camera gateway 192.168.2.1 both plug into comcast business gateway 10.1.10.1

what i have is a comcast business gateway, ip of 10.1.10.xx with one port feeding another gateway which is for our computer network, those ips are 192.168.1.xxx. The other port on the comcast gateway feeds another gateway which has the camera system, these ips are 192.168.2.xxx. I wanted to separate the two for obvious reasons, we have a large computer network and 40+ cameras, didnt want to jam up the network.

Naturally BI thinks that my lan is 192.168.2.XXX because it is. But in order for the computers on the other side of the comcast gateway to connect to the web interface i would point it to the 10.1.10.xx:81 and everything does work perfect, but my question is in the settings of BI should i change the lan address to 10.1.10.xx in order for me to restrict certain users to lan only operation of the UI? If i restrict users to lan with the way it is, then it wont let anyone on because BI is only recognizing the 192.168.2.xxx as the lan and they are on the other side of that which is on the 192.168.1.xxx. Hope that makes sense.

I know some of you guys are going to say that i should use a vpn, and i most likely will when i get the time to figure this all out. This has been quite the experience. You guys have really helped out tremendously.

One more question. Is there a way to export ALL settings, in case of a failure. I know you can export single cameras but i was hoping for a more solid (easy) back up, with everything. I have tons of hours of setting this up, losing it or having to redo this would be horrible.
 

bbarenz

Young grasshopper
Joined
Oct 31, 2015
Messages
49
Reaction score
9
Location
Nebraska
I'm not entirely clear on your setup or the objective but it sounds like you have 192.168.1.x requests sent to 10.1.10.1:81 port forwarded to the BI server on 192.168.2.x. This would allow all local computers to access the BI server and WAN users if you have the WAN side port forwarding enabled in 10.1.10.1. If this setup is working well and you only want to restrict certain users to LAN there is a LAN Only setting within BI user setup to restrict them to LAN access only.

upload_2017-5-11_10-16-30.png

Is this correct for your current setup?

upload_2017-5-11_10-18-35.png
 
Top