Thoughts on Easy/Moderate Secure Home Network Setup with 7 POE IP Cams/Blue Iris + Locks/Doorbells/Zwave (Adding Home Assistant) Tailscale/OpenVPN?

nutshellml

Getting the hang of it
Joined
Jun 22, 2016
Messages
170
Reaction score
10
Morning All –

Background
I’m moving back to my home and wanted to take advantage to start with securing my home network. Gear is 7 POE IP cameras run with Blue Iris, Wifi/ZWave Locks/Doorbells, Always on PCs AND I’m adding Home Assistant (most likely with w Raspberry Pi5) . In past I didn’t have much security setup and used Blue Iris wizard for port forwarding etc – but not sure I want to do that moving forward as i'm trying to avoid port forwarding and firewall exceptions.

Wants
  • Easy>Moderate Secure home network, I’m fairly tech savvy but don’t want to mess with VLANs. Many have recommend Tailscale and/or OpenVPN
  • Separate Guest WiFi so they can’t access network – Think I can do that fairly easily with built in Router/Access Point setup
  • When sitters are in the home network – have them able to access the cameras (I’ve don’t that before w/ Blue Iris user name)
  • Easy access for wifey when she wants to view camera while outside the home network.
  • ** For those that use home automation/Home Assistant or similar – I would like to still be able to utilize Geofencing in scenes and not have to “click on a VPN” is that possible?
  • ?QUESTION? - Will setting up VPN/Tailscale compromise data speed?

Thanks in advance for any advice.

Happy Sunday!
 
Last edited:
Joined
Aug 8, 2018
Messages
7,804
Reaction score
27,583
Location
Spring, Texas
I've used Tailscale in the past, but am now relying on ZeroTier to access the BI server from outside my LAN.

I have my cams on a separate sub-net from the rest of my LAN. That sub-net is not connected to the internet. I do not use VLANS but instead use a second NIC in the BI server and one in my office PC. See the figure.

ZeroTier is easy to set up and I can access my BI server from my laptop while on the road. I also use the BI iPhone app via ZeroTier. Works just fine. Have not noticed any data speed issues.

Network Topology 4.JPG
 

nutshellml

Getting the hang of it
Joined
Jun 22, 2016
Messages
170
Reaction score
10
I've used Tailscale in the past, but am now relying on ZeroTier to access the BI server from outside my LAN.

I have my cams on a separate sub-net from the rest of my LAN. That sub-net is not connected to the internet. I do not use VLANS but instead use a second NIC in the BI server and one in my office PC. See the figure.

ZeroTier is easy to set up and I can access my BI server from my laptop while on the road. I also use the BI iPhone app via ZeroTier. Works just fine. Have not noticed any data speed issues.

View attachment 200326
THANKS! This is super helpful. Do you have any home automation or IoT devices? If so, do you do that same for that and can they talk to each other??
 
Top