Isolate NVRs behind a second router?

JPmedia

Known around here
Sep 11, 2024
1,516
1,448
Southeast
Is it possible to isolate the NVR(s) behind a second router? Can it work and is there any potential issues doing this? I'm just trying to make it harder for someone to find and hack the NVRs
 
I tried this once too. It doesn't work

The problem is the 2nd router gives unfettered access to main router.

Let me see if I can find the post that pointed it out.
 
  • Like
Reactions: bigredfish
So, the NVR accesses the first router through the second router then? How about traffic coming the other way like from the outside? Someone on the outside would have to get through the first router to be able to attempt to access the second router in line, yes? By the way, there would be no Wi-Fi accessibility on the second router, only hard-wired ethernet cables.
 
if you're isolating it behind a 2nd, but then opening it (and the first) to the internet via port forwarding, then you're not protecting anything at all.

The only way it might work was if you had a VPN to the 1st router and that coudl access the NVR via the 2nd....but then why not just have an vpn endpoint on the 2nd router in the first place.

I really dont see any benefit at all. You'd be better to vlan it off and/or only ever allow access via a vpn
 
  • Like
Reactions: bigredfish
It can be done, but gets rather messy, use a single router with even basic VLAN and firewall capabilities - it will be much cleaner and probably more secure.
 
  • Like
Reactions: bigredfish
It can be done, but gets rather messy, use a single router with even basic VLAN and firewall capabilities - it will be much cleaner and probably more secure.
I have NO idea how to set up a VLAN for the NVR(s). I'm not even sure if I have the proper equipment to do so. My goal is to help prevent the NVR(s) from being hacked by outside sources.

I have a feeling that I have an account on my old NVR which just bypasses the main admin account. I can't remove it and it seems someone has unrestricted access to the NVR. Before I go and set up a new NVR, I want to try and protect it from someone repeating the same move.

It's quite frustrating to say the least
 
"My goal is to help prevent the NVR(s) from being hacked by outside sources."

how are you providing access to your NVR? port forwarding? And then exposing NVR to login? regardless if you go dual router, or every put it behind cloudflare tunnels, the biggest weakness is letting the NVR authenticate someone.

Remove the public exposure for the NVR and use a vpn, a vpn via tailscale or cloudflare access where there is a more secure authentication is "safer".
 
  • Like
Reactions: bigredfish
Many routers allow a port (or maybe the last port) to be VLAN with a simple radio button in the GUI. But that only prevents it from hacking i to your other devices.

But yes hosting your own VPN is what most feel is the best way to isolate your NVR as close to an air gap as possible.