Turn off P2P to Dramatically Reduce WAN Access Attempts

guykuo

Getting comfortable
Jul 7, 2018
706
2,046
Sammamish, WA
I thought I had all my web services turned off in my Dahua cameras. They also live in an isolated network that doesn't allow DNS lookups. Despite those restrictions, my router kept showing the cameras attempting to contact the outside world. Stats showed thousands of camera to WAN connection attempts were being blocked by my EdgeRouterX.
Screen Shot 2020-01-21 at 3-1.37.09 PM.jpg

Turns out I failed to turn off Access Platform P2P in some of my Dahua cameras.
Dahua P2P runs even if you don't allow the cameras DNS lookups.

Disabling P2P dramatically reduced the undesired connection attempts.
 
Last edited:
Safest is to VPN into your network to view the cameras. Then you proceed as though on your home network.

Second, somewhat less safe alternative, is to port forward into your recording PC's BlueIris or SecuritySpy web service.

Less safe is port forwarding to your NVR.

Completely unrecommended, horrible option is to port forward directly to your cameras.
 
yeah i knew port forwarding was out the window, but enabling P2P is safe via VPN? blue iris is out for me, ordering an NVR whenever andy gets back.
 
and is there a physical piece of hardware that'a vpn or firewall that is beneficial or do i just plug the camers into the nvr and then run a ethernet cable into the swtich and buy something like nordvpn or openvpn (can't think of the good one off the top of my head).
 
and is there a physical piece of hardware that'a vpn or firewall that is beneficial or do i just plug the camers into the nvr and then run a ethernet cable into the swtich and buy something like nordvpn or openvpn (can't think of the good one off the top of my head).
you must read the wiki on securing your network. If you suggest nordvpn it indicates you have not.
 
  • Like
Reactions: JDreaming
and is there a physical piece of hardware that'a vpn or firewall that is beneficial or do i just plug the camers into the nvr and then run a ethernet cable into the swtich and buy something like nordvpn or openvpn (can't think of the good one off the top of my head).
Netcelero