Improving Dahua Camera Security

cdre

n3wb
Joined
Dec 27, 2017
Messages
4
Reaction score
1
Hi, I've been running a few Dahua bullet cams and and just added a few more turret and PTZ versions. Very happy with them and primarily use them with my Milestone server.

I've heard these cameras "phone home" so I want to control external comms a little. At the router level, I'd like to blacklist all ports not used for the purpose of email notifications. I'm using gmail which works at port 587. I blacklisted all ports other than 25 and 587 but am getting email test failures at that setup. Success when not blacklisting, so there is a port dependency I'm not aware of.

Any recommendations on getting this working or otherwise securing my cameras better? Obviously firmware updates and password are table stakes. I would deny them access to the gateway server and view exclusively through Milestone but want to get email working if I can... Already killed port forwarding to my server and viewing remotely only through a VPN.
 

BubbaJoe

Getting the hang of it
Joined
Nov 29, 2017
Messages
96
Reaction score
21
Turn Upnp off on the router and cameras. Give the cameras a 1.0.0.1 dns and just use your vms to get e-mails. Not sure if you can use milestone for that purpose. With blue iris you can setup emails thru the vms.
 

cdre

n3wb
Joined
Dec 27, 2017
Messages
4
Reaction score
1
Thanks Bubba. Unfortunately Milestone's free server doesn't allow email alerts (as far as I know). Otherwise it's super capable....
 

giomania

IPCT Contributor
Joined
Jun 1, 2017
Messages
780
Reaction score
538
I assume you saw the “Dahua camera best practices“ post linked and summarized in my cliff notes post? It sounds like you have a handle on this, but you may see something useful in there. See the link in my signature.


Sent from my iPhone using Tapatalk
 
Top