Security practises to mitigate risks
To all the network experts:
I want to install a system for a couple of clients. 4-6 Hikvision cameras + NVR etc. Recently more people have been questioning the company's ie hiks OEM integrity ie with CCP etc.
So my question is related to security and what risks remain from the following implmentation:
1. If I take the following steps, does it completely mitigate any security risks
- connect the hiks to a macmini with SS ie No Hikvision NVR
- Run a VPN to access SS remotely
- implement a firewall policy to block outgoing connections from the cameras to anywhere but the macmini
- I can further create a lot VLAN
or
2. consider a different manufacturer but I will still need to put the above network policies to mitigate security risks
Thanks!
I want to install a system for a couple of clients. 4-6 Hikvision cameras + NVR etc. Recently more people have been questioning the company's ie hiks OEM integrity ie with CCP etc.
So my question is related to security and what risks remain from the following implmentation:
1. If I take the following steps, does it completely mitigate any security risks
- connect the hiks to a macmini with SS ie No Hikvision NVR
- Run a VPN to access SS remotely
- implement a firewall policy to block outgoing connections from the cameras to anywhere but the macmini
- I can further create a lot VLAN
or
2. consider a different manufacturer but I will still need to put the above network policies to mitigate security risks
Thanks!
Comments
-
I have 12 cameras connected to a Hikvision NVR. I disabled the Hikvision remote access and connected SS to it. Now it can only be accessed via SS. There are a few settings which you need to make on the NVR like removing encryption to make it work with SS but I have had a very good experience with it. In addition you can access the images using a browser which you can't do with Hikvision at the moment because the plugin they used to use is no longer working with the latest browsers.
-
I think the best thing you can do is put all cameras on their own separate LAN that has no Internet access, described here: Segregating IP Cameras on their own LAN. If you do this, there is no way for the cameras to make any connections to the Internet.
Once you have done this, use SecuritySpy in the normal way (e.g. set up Remote Access normally without a VPN). And there is a no need for a firewall to block outgoing connections, because the cameras can't make them anyway. -
Thanks Dave Ill keep the SSL setting in mind.
Ben, disabling internet access to the cameras network makes sense. Instead of dual ethernet which I dont have, couldn't I just use a VLAN -
Yes, you can certainly use a VLAN for this if you switch supports it and you are familiar with the setup, which can be a bit complicated.
