Redoing network need help isolating cameras.

avery155

n3wb
Joined
Oct 4, 2018
Messages
5
Reaction score
1
Location
USA
Hello everyone,

I have been reading through some of the camera isolation threads and various ways to do it. I however can figure out what the best option for my setup will be.

Tomorrow a edge router x, and a unifi 8port poe switch is comming, as well as some other things.

So my delimma.

Blue Iris will be running on my main machine as it is currently and all data gets stored on a NAS nothing locally.

With this new setup I will be adding in nanobe access points to an out building.

My problem is, I would like to be able to have internet access out there as well as run my cameras.

So one Ethernet port for my wan, one Ethernet port to my house lan with the blue Iris machine and other devices.

Another port to the unifi switch, that connects to nano beam to the other nanobeam. That goes to a dumb switch with 3 cams and a ubiquity ac point.

How can I secure it so cams can only talk to just the PC while retaining internet access for the AP.

One last question with 24/7 recoding BI set write direct to disk does the data flow through BI machine then to NAS or straight to NAS. NAS will be on unifi switch.

Any help would be great retaining internet out at the out building is what's messing me up. As far as subnet or vlans go.

I'm not sure if I can group Mac addresses or static ip's in the router to drop or reject any outgoing request to the wan?


Also BI machine has only 1 NIC
 

bababouy

Known around here
Joined
Mar 29, 2015
Messages
1,053
Reaction score
1,630
Location
almost to the bottom
Was gonna ask about the NIC, then read the last line. Does the Edge have two LAN ports? If not, you could add a dual NIC to the PC. Set your cams on a separate subnet. The USG-PRO-4 has a dual LAN set up.
 

avery155

n3wb
Joined
Oct 4, 2018
Messages
5
Reaction score
1
Location
USA
Yes I believe I can set up wan, lan 1, lan2 won't know for sure untill I get it.
 

catcamstar

Known around here
Joined
Jan 28, 2018
Messages
1,659
Reaction score
1,193
Yes I believe I can set up wan, lan 1, lan2 won't know for sure untill I get it.
I do have an ER-X deployed in my environment, it has 5 physical ethernet ports. It can do Physical Vlan ID per port, or Vlan Tagging per port. So depending on how you want to work (you have "the easy" way and the "less easy" way), you can opt for:
- creating a "flat" network, WAN port on ETH0, and all the other ports in 1 network (eg. 1 vlan), with the difference that you can make (for example) 2 subnets: 1 DHCP range with the cams in, and 1 DHCP range for your "home LAN", including your BI. Within the firewall capabilities of the ER-X, you can then make a routing rule between these two subnets with (for example) that ALL CAMS can speak with BI, but not with everything else in your home LAN, and that BI can "talk back", but only your mobile phone (and not the ones of the kids). This does require some "maintenance", if your phone breaks, you have to enter all new configurations within the ER-X. However, if someone/something "changes" the IP stack on one of your devices, it can easily "jump" into another subnet.
- creating a "layered" network, WAN port on ETH0, VLAN1 on ETH1 and VLAN2 on ETH2 (for example). You make sure that these vlans get propagated properly into the switches downwards. The concept of the firewall rules remain the same: YOU define the traffic coming IN and going OUT of each VLAN (like in the use case above), however you are relieved from some maintenance, as you can say that all WLan traffic automatically ends up in VLAN2 (visitor-wifi) which can only go to the internet between 7:00 and 19:00. The same with physical network ports: whatever you plug in, this device can never "jump" into another VLAN, even when someone/something changes the IP stack on the device.

There are tons of tutorials on the ER-X on the internet, it took me less than 1 hour to implement the latter scenario, which suited my needs the most. My advice: evaluate your exact needs, the willingness to have the utmost secure environment (as if that would even exist), and off you go!

Good luck!
CC
 

avery155

n3wb
Joined
Oct 4, 2018
Messages
5
Reaction score
1
Location
USA
Thank you so much, I will try and Implement what you have reccomended. I have read and watched a plethora of information while waiting for everything to get here. Everything has been delivered today when I get home I will get some hands on with it and I think that will clear up some of my confusion with it.

G
 
Top