VLAN via USG for Secure Camera Setup - Please Help

elitef

Getting the hang of it
Joined
May 25, 2015
Messages
153
Reaction score
32
Hello All,

Hoping someone can help me out. I have a few days off from work and hoping to be able to set things up the correct way.

My current setup is as follows:

Fios ONT > Ubiquiti Unifi USG > Ubiquiti Unifi 48 Port POE Switch > ports 40-48 are to cams via POE.
I have a mixture of Dahua and Hik cams for indoors and outdoors.

On Port 39, I have a Synology Diskstation running Surveillance Station which records all the cameras 24/7.

I currently have it that nobody can access the server except from being within the network, so I've set up a VPN in USG.

Currently I have each cam configured separately where all the functions of uPNP are turned off, no web access (or so I think), etc...

I am wanting to set make it even more secure and wanting to set up a VLAN within USG and put the cams on it. I am unsure if I should add the server on there as well since I want to continue accessing the server from within the house, but not be able to access the cams from within the network (say a guest comes, connects to my wifi, and if they know the IP's to be able to navigate to each cam individually, etc.)

So hoping someone can shed some light as to how I can go about doing the following things:
- Securing my network and cameras via separate VLAN
- Advising on how I can check to make sure the cameras currently arent talking to the internet
- Server on or off that VLAN

Any help would be greatly appreciated.
 

giomania

IPCT Contributor
Joined
Jun 1, 2017
Messages
780
Reaction score
538
I am a novice running UniFi, so take this with a dose of skepticism, unless verified by one of the Network gurus here.

I put my cameras and the PC with Blue Iris on a separate VLAN (CamLAN) that cannot access the Internet. Each switch port with a camera and the BI machine are configured for the CamLAN VLAN.

To be sure the cameras aren’t accessing the internet, I set up a firewall rule for each camera (via MAC address) to deny access from CamLAN to both the secure LAN and WAN.

I can access CamLAN from the secure LAN, and I think that is the default UniFi setup.

Mark


Sent from my iPhone using Tapatalk Pro
 
Top