Dahua - Unifi USG VLAN

davw

Getting the hang of it
Joined
Mar 7, 2017
Messages
147
Reaction score
30
Location
England
Hi I have a Dahua NVR and 2 x IPC-HDW5231R
Just got a Unifi USG but have an unmanaged Netgear POE Switch
To improve security is it advisable to create a VLAN and stick the Dahua gear in it?
Any guides on how to do this please?
Or what is the best way to stay safe.
cheers
 

Ep1phany

n3wb
Joined
Jul 11, 2019
Messages
3
Reaction score
0
Location
Calgary
Hi I have a Dahua NVR and 2 x IPC-HDW5231R
Just got a Unifi USG but have an unmanaged Netgear POE Switch
To improve security is it advisable to create a VLAN and stick the Dahua gear in it?
Any guides on how to do this please?
Or what is the best way to stay safe.
cheers
I use a USG. My cameras are all on their own vlan / subnet so they can't see the rest of my network. I use firewall rules on the USG to drop connections from that vlan to everything else including the internet. Works fine.

With a Unifi USG you still need a managed switch to configure different vlan's and subnets to specific ports on the switch.

Just search for a vlan tutorial for the USG, or a more general tutorial about vlans. It doesn't have to be specific for Dahua.
You'll also have to review how to create firewall rules on the USG.

Hope that helps, sorry I don't have any saved tutorials to share with you.
 

mikeynags

Known around here
Joined
Mar 14, 2017
Messages
1,034
Reaction score
940
Location
CT
You'll need a managed switch that supports VLANs. You can put in firewall rules on the USG to block the cameras from phoning home. If you are a fan of Unifi gear, look at the Cross Talk solutions, Lawrence Technology Systems or Wille Howe Youtube pages. They cover some extensive topics on the entire Unifi line and also things like setting up VLANs.
 

davw

Getting the hang of it
Joined
Mar 7, 2017
Messages
147
Reaction score
30
Location
England
thanks guys. not looking to spend on a managed switch yet.
anything i can do with what i have?

Also is putting a vpn on usg do-able?
 

mikeynags

Known around here
Joined
Mar 14, 2017
Messages
1,034
Reaction score
940
Location
CT
thanks guys. not looking to spend on a managed switch yet.
anything i can do with what i have?

Also is putting a vpn on usg do-able?
Yes - here is a link to some instructions on setting it up from Unifi

 

DLONG2

Known around here
Joined
May 17, 2017
Messages
763
Reaction score
455
thanks guys. not looking to spend on a managed switch yet.
anything i can do with what i have?

Also is putting a vpn on usg do-able?
An 8 port 60W PoE Ubiquiti switch runs about $108. You could assign one of the eight ports as the camera VLAN.
 
Joined
Sep 29, 2020
Messages
26
Reaction score
1
Location
USA
An 8 port 60W PoE Ubiquiti switch runs about $108. You could assign one of the eight ports as the camera VLAN.
could I just plug in the NVR to the one port, assign the vlan and call it a day? would I need the other Ubiquiti routers, etc?
 

McBud

n3wb
Joined
Aug 4, 2019
Messages
3
Reaction score
0
Location
Texas
could I just plug in the NVR to the one port, assign the vlan and call it a day? would I need the other Ubiquiti routers, etc?
I have the US-8-60W and thing runs hot. 101F on the bottom of the unit with only the power plug connected to it. I think you may need the USG to setup the switch.
 

STGMavrick

Young grasshopper
Joined
Mar 5, 2018
Messages
41
Reaction score
22
I use a USG. My cameras are all on their own vlan / subnet so they can't see the rest of my network. I use firewall rules on the USG to drop connections from that vlan to everything else including the internet. Works fine.

With a Unifi USG you still need a managed switch to configure different vlan's and subnets to specific ports on the switch.

Just search for a vlan tutorial for the USG, or a more general tutorial about vlans. It doesn't have to be specific for Dahua.
You'll also have to review how to create firewall rules on the USG.

Hope that helps, sorry I don't have any saved tutorials to share with you.
I do the same as you. Vlan specific to all cameras + NVR. Camera firewall rules are switch port based to drop all traffic except to the USG for NTP sync. NVR port shares the same rules as the main network vlan.
 

Juristo

n3wb
Joined
Sep 28, 2015
Messages
11
Reaction score
2
thanks guys. not looking to spend on a managed switch yet.
anything i can do with what i have?

Also is putting a vpn on usg do-able?
Do you have a Raspberry Pi? You could install Pihole and blacklist the domains you see it reaching out to. That's what I'm doing until I figure out this VLAN stuff.
 

bob2701

Getting comfortable
Joined
Jan 7, 2016
Messages
1,009
Reaction score
482
Location
Jersey Shore
How about $29 for a managed switch?? :rolleyes:

Check out the Mini Flex.

 

davw

Getting the hang of it
Joined
Mar 7, 2017
Messages
147
Reaction score
30
Location
England
hi i have just set up pihole
still trying to work it out :)
 

davw

Getting the hang of it
Joined
Mar 7, 2017
Messages
147
Reaction score
30
Location
England
i currently have Virgin Media Modem > USG > POE switch 1 with 2 IP cams and 1 Unifi AP connected > cable running to loft space attached to another POE switch connected to NVR and another unifi AP
where would the USW flex go?
 
Top