Thank you for taking the time to respond. I may consider your solution down the road as I get more experience managing my network. For now I am going stick with the more common approach that I already have configured and look for the best ACL's to use. Thanks AgainPersonally I set them up on a completely different IP subnet and do not run it thru the router.
Then add another ethernet port to the BI computer and have the internet go to one ethernet port and the cameras going to the other ethernet port.
jeremyx, Thank you very much for taking the time to respond. Your input is very helpful. My system consists of an Omada gateway, controller, and a smart switch. Currently, the BI PC and cameras are in their own VLAN with the goal of eventually isolating surveillance from the rest of the networks. Traffic is trunked between the gateway and switch and seems to be working ok. I would hesitate putting the BI PC into Trusted. Are you suggesting that I put it in its own VLAN? Can you help me understand the benefits of isolating the cameras from the NVR? I am still a novice at networking. I will have to chew on your second paragraph for a bit to fully understand it. Thanks for the suggestion to turn off P2P and UPnp on the cameras themselves. I would have missed that. Since I am not yet remoting, I use UI3 only internally. Outside the network I am on a VPN. Again, thank you very much for your input. Great food for thought.If you want to do it with a VLAN on a managed switch and router instead of a second NIC, this is the layout most people end up with:
Put the cameras on their own VLAN and subnet (for example 192.168.20.0/24). On the router/firewall, allow the BI PC to start connections to the camera subnet on RTSP 554 and the cameras' HTTP/ONVIF port, and allow established/related return traffic. Then deny anything the camera VLAN starts toward the main LAN and the internet. The only exception worth adding is NTP from the cameras to the router or the BI PC, so their clocks stay right without internet access.
From the main LAN side, block access to the camera VLAN for everything except the BI PC, plus one admin PC if you want to reach the camera web pages directly.
On the cameras themselves, turn off P2P, UPnP and any cloud services so they are not constantly trying to phone out. For remote viewing, VPN into the main LAN and use UI3 on the BI PC rather than forwarding any ports.
One thing to watch: with the BI PC on the main LAN, all camera streams get routed between VLANs by the router, so make sure it can handle the combined bitrate. If it struggles, giving the BI PC a second NIC on an untagged camera VLAN port keeps that traffic off the router.
