Install the app
How to install the app on iOS

Follow along with the video below to see how to install our site as a web app on your home screen.

Note: This feature may not be available in some browsers.

RT2600ac Firewall Entries for cameras as a: Make Darn Sure!!!

2,663
509
NAS
DS 718+, 2x-DS 720+
Router
  1. RT2600ac
Operating system
  1. Windows
Mobile operating system
  1. iOS
Last edited:
A few years back, after learning that my HikVision camera's were being 'obsoleted', even though they still looked and ran fine! They would never get another security or firmware upgrade (Learned this in midst of HikVision Security Issue... This simplified the work-load on firmware writer's - apparently!)
Seeing that I only accessed cameras via Surveillance Station, I started in to isolate the cameras from the web..

When I started adding 4K cameras, that worked, but with no firmware updates that I could find...This became even more important... I had heard of cameras: "Phoning Home", and other weird things.... I didn't want ANY OF that...

I first experimented with & Still using, a BOGUS GATEWAY with no access to internet. First just entering an IP that didn't exist... This worked, but flooded the LAN with Messages.... The moment that was added the large amount of "WHERE IS? BOGUS GATEWAY IP" messages sent by each camera to all other devices on the LAN.
This was reduced to none... by taking an old router and giving it that IP, connecting it's LAN to my LAN, but then never connecting the WAN anywhere.... That ceased all WHEREIS messages....

But wondered: Would anything be smart enough to find the real Gateway? So I decided to do one more layer.... in 2600 Firewall (Real Gateway!) I added 4 rules... Placing them at top of list, in area I refer to as: Should Never Get 'Hits'!
1 deny for incoming TCP/UDP to Cam IP Range..
1 deny for outgoing TCP/UDP from Cam IP Range..
1 deny for incoming ICMP to Cam IP Range...
1 deny for outgoing ICMP from Cam IP Range...

Synology Router's Firewall can support 127 rules.... adding 4 didn't slow anything down.. on 2600.

Many years later.... No HITS on the 4 rules that I've ever seen! LAN is quiet regarding WHERE IS messages.... No issues with any cameras....
May not be elegant.... But it seems to be working!
 
Do you think that using the "Banned" settings under Network Center/Traffic Control for the IPcam device is not sufficient or that it's something that I should not rely on?

1760213936832.png
 
Last edited:
Wasn’t aware of that used what I knew about.
Does that give ‘hits’, or more info: about which, when or to who?
firewall gave at least hits, if no hits no problem. .
Please explain
 
no hits, it just restricts the device from the internet connection. on LAN it works as expected, according to firewall rules etc. With Surveillance Station it works without any hassle.
 
I specifically wanted the warning hits would give!
If No hits - no problem!
If Hits! — Then I know that something ‘unusual’ has happened, and I then need to do ‘something more’!

In your case, you get no warning that something bad has happened. So you continue on un-aware……..

I want that extra warning! I like my approach better.
 
I specifically wanted the warning hits would give!
If No hits - no problem!
If Hits! — Then I know that something ‘unusual’ has happened, and I then need to do ‘something more’!

In your case, you get no warning that something bad has happened. So you continue on in-aware……..

I want that extra warning! I like my approach better.
Yes sure, I like being able to check hits as well, if possible. Better control.
My tip was just about saying that there may be a simple option for completely cut off the device from the internet. Which can be useful and is easy to use.
 
Last edited:
Yes, but if you go your way, you get no feedback! I don’t see it as better control at all, unless it had hits, or info: to who; when; to where?

Again.. With your way if a camera started to phone home or something bad due to malicious code…. You are not informed it occurred!!!! So it can continue on - trying to do: _________…. 😱

Hits on firewall, in combination with a rule that in theory, should never, ever, get hits…. Gives you more information! (Why I wish hits were on NAS firewall. This approach cannot be used on NAS!)

If I ever see hits on those 4 rules…. I know that something I’m not expecting to ever happen, has happened on cameras that are no longer supported by MFG. I can then Do Something….(reset & reload firmware, or ??) Because I Have been warned!

Further info in logs would be nice, and preferred, but it is not available in router. So I created this as a way to get more information with the tools we have been given.
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Similar threads

Oh My! I must still be tired from the multiple flights!!! 👍 Thank You! QC Revision. Connects via QC on...
Replies
4
Views
62
The WRX560 is connected to the RT6600ax by ethernet - using the 2.5 Gbps sockets on both units. The...
Replies
2
Views
137
I'm finding that if I have a firewall rule: TCP/IP ALLOW, Source IP of Router, to ALL destinations.... and...
Replies
0
Views
178
Do have 2 other routers on LAN. (Neither Synology): One is in garage, wired, at .20, And is a 5Ghz WIFI...
Replies
9
Views
348
Well make sure you don’t have a time server issue before update. (He said - based on experience!) Now...
Replies
11
Views
907

Welcome to SynoForum.com!

SynoForum.com is an unofficial Synology forum for NAS owners and enthusiasts.

Registration is free, easy and fast!

Trending content in this forum

Back
Top