Best Practices for Configuring VLAN's and ACL's

cjamt

n3wb
Nov 17, 2023
16
1
Montana
Can anyone provide me with the pest practices for setting up a Surveillance VLAN and configuring ACL's for a network with a PC based NVR running BlueIris V6 . Thank you.
 
Personally I set them up on a completely different IP subnet and do not run it thru the router.

Then add another ethernet port to the BI computer and have the internet go to one ethernet port and the cameras going to the other ethernet port.
 
If you want to do it with a VLAN on a managed switch and router instead of a second NIC, this is the layout most people end up with:
Put the cameras on their own VLAN and subnet (for example 192.168.20.0/24). On the router/firewall, allow the BI PC to start connections to the camera subnet on RTSP 554 and the cameras' HTTP/ONVIF port, and allow established/related return traffic. Then deny anything the camera VLAN starts toward the main LAN and the internet. The only exception worth adding is NTP from the cameras to the router or the BI PC, so their clocks stay right without internet access.
From the main LAN side, block access to the camera VLAN for everything except the BI PC, plus one admin PC if you want to reach the camera web pages directly.
On the cameras themselves, turn off P2P, UPnP and any cloud services so they are not constantly trying to phone out. For remote viewing, VPN into the main LAN and use UI3 on the BI PC rather than forwarding any ports.
One thing to watch: with the BI PC on the main LAN, all camera streams get routed between VLANs by the router, so make sure it can handle the combined bitrate. If it struggles, giving the BI PC a second NIC on an untagged camera VLAN port keeps that traffic off the router.
 
Personally I set them up on a completely different IP subnet and do not run it thru the router.

Then add another ethernet port to the BI computer and have the internet go to one ethernet port and the cameras going to the other ethernet port.
Thank you for taking the time to respond. I may consider your solution down the road as I get more experience managing my network. For now I am going stick with the more common approach that I already have configured and look for the best ACL's to use. Thanks Again
 
If you want to do it with a VLAN on a managed switch and router instead of a second NIC, this is the layout most people end up with:
Put the cameras on their own VLAN and subnet (for example 192.168.20.0/24). On the router/firewall, allow the BI PC to start connections to the camera subnet on RTSP 554 and the cameras' HTTP/ONVIF port, and allow established/related return traffic. Then deny anything the camera VLAN starts toward the main LAN and the internet. The only exception worth adding is NTP from the cameras to the router or the BI PC, so their clocks stay right without internet access.
From the main LAN side, block access to the camera VLAN for everything except the BI PC, plus one admin PC if you want to reach the camera web pages directly.
On the cameras themselves, turn off P2P, UPnP and any cloud services so they are not constantly trying to phone out. For remote viewing, VPN into the main LAN and use UI3 on the BI PC rather than forwarding any ports.
One thing to watch: with the BI PC on the main LAN, all camera streams get routed between VLANs by the router, so make sure it can handle the combined bitrate. If it struggles, giving the BI PC a second NIC on an untagged camera VLAN port keeps that traffic off the router.
jeremyx, Thank you very much for taking the time to respond. Your input is very helpful. My system consists of an Omada gateway, controller, and a smart switch. Currently, the BI PC and cameras are in their own VLAN with the goal of eventually isolating surveillance from the rest of the networks. Traffic is trunked between the gateway and switch and seems to be working ok. I would hesitate putting the BI PC into Trusted. Are you suggesting that I put it in its own VLAN? Can you help me understand the benefits of isolating the cameras from the NVR? I am still a novice at networking. I will have to chew on your second paragraph for a bit to fully understand it. Thanks for the suggestion to turn off P2P and UPnp on the cameras themselves. I would have missed that. Since I am not yet remoting, I use UI3 only internally. Outside the network I am on a VPN. Again, thank you very much for your input. Great food for thought.
 
Many here do the dual NIC route.

On my isolated camera NIC, my cameras are streaming non-stop 350Mbps. This is full-on, never stopping to take a breath. Even if someone has a gigabit router, a 3rd of non-buffering 24/7 data will impact its speed.

If I didn't have dual NIC, then I could potentially be having 350Mbps incoming and watching multi-camera on mainstream at 350Mbps, so I am now pushing 700Mbps thru a gigabit ethernet port and other devices. And most GB routers and devices cannot push that through. For example, the EdgeRouter X is claimed to be 1Gbps, but you see tests all over where people are only getting in the 700Mbps range.
 
wittaj,

Thank you again. This is very helpful. Again, I am a novice so take that for what it is worth. In my network the gateway has 2 multi gbps ports. One is connected to the modem the other is vacant. The network trunk is on one of the 1Gbps ports. The switch does not have multi Bbps capability. What about aggregating 2 Gbps ports? Anyway, I am going to pass your comments to a friend who is my networking mentor. Thanks again. You have been very helpful.
 
I use two primary questions to determine how to determine what VLAN a device should go on. 1) Do I trust this device/does it actually need access my most private/personal data? and 2) Does this device need access to the internet? I have four VLANs and place devices inside one of the four based on the answers to these questions.

VLAN A - "Trusted network." - Only devices that need to access the most secure parts of my network belong here. Network devices (router, switches, etc), servers, trusted computers, and my most trusted data (NAS).

VLAN B - "Not Trusted with internet access." - 80% of all devices will probably fall on this network. Anything that I don't trust with (or doesn't need to access to) my most private data, but needs to access the internet belongs here. All mobile devices (phones, tablets, etc), untrusted computers (work computer, kids computer, etc), TVs and media steamers, IOT devices that need internet to function, etc all belong here.

VLAN C : "Not Trusted without Internet." - Things I don't trust, but also don't need to access the internet belong here (cameras, network printers, other IOT devices that shouldn't touch the internet, etc). If you want to break this into more VLANs (one for cameras, one for PBX phone system etc) you can, but I feel it is overkill and a more appropriate way to handle this is through firewall aliases and ACL rules (see note below).

VLAN D: "Guest Network." - Effectively this is a "not-trusted with internet access" VLAN, but for devices that I don't want accessing ANYTHING else on the network. Obviously devices that guest bring into my house fall into this category, but I can also put other "really not trusted" devices if I need that level of network isolation for any personal devices too.

This is a pretty "over simplified" look at my network. I definitely use firewall aliases and firewall rules to determine what devices have access to other devices (within the same VLAN or across VLAN). I feel that far too often people resort to using VLANs for this purpose and it causes people to "over segment" their network with too many VLANs which in turn causes unneeded congestion on the network/router. I guess if I set my switches up as true Layer 3 devices (and forgo the router completely) this wouldn't be a concern, but that is more work than it is worth IMHO for a normal home network.

PS - Having two "not-trusted" VLANs (one with internet and one without) makes it super easy to manage what devices can access the internet and what devices cannot access the internet simply by placing them in the appropriate VLAN. (This is a situation where a VLAN is better than combining all of those devices into one VLAN and then trying to use firewall aliases/ACLs to manage access to the internet).
 
Last edited: