VPNs for Video Surveillance

Author: IPVM Team, Published on Feb 07, 2017

Remote access in surveillance networks is a key cyber security and usability issue. With cyber attacks rising, how can users ensure their systems are secure without losing access from outside the network?

Virtual private networks (VPNs) have historically been used in complex / large systems to secure data but can also be used in smaller sites with relatively inexpensive. To better demonstrate this we purchased two Dell SonicWall SOHO routers and configured them to simulate a site to site VPN.

Inside, we look at VPN usage in video surveillance, including the following topics:

  • What is a VPN?
  • VPN protocols
  • VPN topologies
  • VPN price considerations
  • Benefits and drawbacks
  • Site to site VPN configuration
  • Remote access VPN configuration
  • Mobile device usage
  • Recommendations for VPN use

****** ****** ** ************ ******** ** * *** ***** ******** and ********* *****. **** ***** ******* ******, *** *** ***** ensure ***** ******* *** ****** ******* ****** ****** **** ******* the *******?

******* ******* ******** (****) **** ************ **** **** ** ******* / ***** ******* ** ****** **** *** *** **** ** used ** ******* ***** **** ********** ***********.** ****** *********** **** ** ********* ******* ********* **** ********** ********** **** ** ******** * **** ** **** ***.

******, ** **** ** *** ***** ** ***** ************, ********* the ********* ******:

  • **** ** * ***?
  • *** *********
  • *** **********
  • *** ***** **************
  • ******** *** *********
  • **** ** **** *** *************
  • ****** ****** *** *************
  • ****** ****** *****
  • *************** *** *** ***

[***************]

Virtual ******* ********

* *** ** * ******* ******* **** ******* * ****** tunnel **** *** ******** ** ******* *** ** **** *********. These ********* *** ** * *** *********, * ***********, ** a ****** ******. ********** ******* * ****** ********** **** *** endpoint ** *** ***** ******* **** *******, **** ***** *********** over *** ********. *** *******, ******* ** * ********* ***** of * ****** ******, **** *** *** ********** ** *** up, **** "*********** ****" ** *****, ** ****** ******** *** encrypted.

***** *** ******* *** ******** *******, ***** ****** **** ** level ** ********** *** ****** *************. ***** *******:

** **** ********, *** *** ***** **** ***** **** ***** on ********* *******.

VPN ********

***** *** *** ******** **** *** **********, ***** **** ********* use *****:

  • **** ** ****:* **** ** **** *** ******** ** ********* ** **** locations, ***** *********** ****** *** *** ****** ******** ******** **** a ****** ******* *******. ** ********, **** *** ** **** to ******* *** **********' ****** **** ******** ** **** *** be ******* *** ****** ** ***, **** ****** ********.
  • ****** ******:** * ****** ****** *** ***** ** *** *** ********* (also ***** ** * ************) *** * *********** ***** ******** via ****** ********. **** **** ** *** *** ** **** to ******* ****** ***** ** * ******** ******* *** *******, or *** *************/*************** ***** *** ***********.

** ******* ***** ********** ** **** ****** *****.

VPN *******

**** *** **** ***** *** ** ********* ********, ********* ******** on * ****** ** ********. ******* *** ******** *** ****** depending ** ************ (********* ****** ** *** *******) *** ********** handling. **** *** ** ***** ***, ***** ***** ******** *** ************* **** ******* **** $**,***.

** ******** ** ******** *** **********, ***** *** ******* ******** to **** * ******/** **** * *** ************. *** **** popular ****** *** **** *********, ***** ** ****** ** $**/**** *** ******.

VPN ********/*********

***** *** ***** *** ******** ** ****:

  • ********:******* *** ******* ******* *** ********* ** ********* *** ************/******** devices *** *** ******* ******** ** *** ********, **** ******* improved ***** ******** ******** ** **** **********/****. **** **** ***** services **** *****-*******,****, ***., **** ******* **** *******.
  • ***********:******* **** *** ********* ********, **** *** ********* **** ******** than ***** ***** ******** ** ****, ***** *** ******* ** users' *******.
  • **************:****** ***** ****** ****** *******, **** **** **** *** ***********, allowing ***** ** ********* *** ****** ***** ****** ** * given ****, ***., *** ****** ********.

*******, ***** *** *** ********* ***** **** **** **** **** being **** ******** ****:

  • ****:*** ******** **** **** ** * *******, ***** ************ ***** services *** **** **********/**** *** ********* ****. ******* *** ** most ***** *** ****, ********* * *** ******* *** ***** to $***+/****.
  • **********:*** ***** ******** ** ********* ***** ****/**** ************ ********** ** not *******. **** ***** ***** ** *** ** *****, **** have ***** *** ** *** ********.

Site ** **** *** *******

** ** ******* ** * **** ** **** ***, *** diagram ***** *********** * ************ ******** **** * *** ****** and ******* *******, ***** **** * ********* ****** **** ******** cameras *** * ******* *******. ***** * **** ** **** VPN, *** ****** ******** ******* ********* ** ***.

** ****** *********** **** ** ********* ************ **** ********** ********** **** ** ******** * **** ** **** ***.

Configuration *****

** **** ******* ** ******* *** ***** ***** ** ********* our ******* *** **** ** **** *** ***. *** ***** steps ******** ** ******** ************* ****, *** ********* *** ******** is * ***** **** *******:

****** *** ****** → ****** ******** → ****** ******** ** connect

****** ******

** **** ****, ** ****** *** **** ** *** (**** to ****), ******** ****, *** **** ** * **** *** shared ****** (******* ** * ********, **** ** **** ******* to *******).

****** ***** *** ****** ********

****, ** **** ****** ******** *** **** *** ***** *** remote **** ** ***** ** ****** ******* *****. ***** *** two *** ***** ** **** ****:

  1. **** **** ** ********* ** **** *******. ** ***** *****, in *** *******, ** **** ****** *** ********* ****** ******* (192.168.2.x) ** *** **** *** ** ******, *** *** ********* as ****. *** **** **** ** **** *** *** ** network (***.***.*.*) ** **** *******.
  2. ***** ******** ********** *** **** ****** ** ***** ** ***** ********. **** is *** ** **** ***.***.*.* *** *** ** *** ***.***.*.* for *********.

**** **** ******************, **** ***** ******** *** ******** ** *** "LAN" **** ** **** *******. ******* *** ********* ***** *** "WAN", ********* ******** **** *********** *** ***** ****, ** **** are ***.

****** ******** ** *******

**** **** *******, ** *** *** ****** *** *** ******** to ** ********* *** *** ***. ** *** ** *********, we ****** *** ** ******* ******* ***** ** "*****", *** choose "********* ******" ** *** *********** *******. ** *** ********* Office *********, ** ***** ** *** *******.

****** ****** ** *******

**** ** ********* **** *** ********** **** *** *****, ** can ****** *** ****** ** ******* *** *** *****. ** the ***** *****, ** **** **** *** ***** *** ****** to *********** **** **** ***** ***** *** *** ****** ** established. **** *** *** ** ****** ******* ***** ********** ** ping ******** *** *** ****** *** ** ******** ****** / administered.

Remote ****** ***

** **** ********** ** ** *** ******* ** ****** **** to ******* ** *** *******, *** ***** *** ***** ******* from ******** **** ** ** *** *******. ** *** ******* individual ***** **** *** ******. *** ************* ****** *** **** as * ***** ** ***** ********, ****** *** ******. ***** that ** **** ******* ******** * *** ****, *** *********** the ****** ********.

****** ******

*** ************* ****** **** ******** * *** ****** ** *** appliance ******* ** *** **** **** ******** ******. **** ****** requires *** ********** ****, * ****, *** ****** ******. **** that **** ****** ****** ** ******* **, *** ******** ****, individual **** *********.

****** *******(*)

***** *** ****** ** ***** ** *** *** *********, ** create **** ********. ***** *********** *** **** ** ****** ******* when ********** ** *** ***.

****** ******

*******, ***** *** ******** *** ** **** ******* ***** **** may ****** *** *** ***. ***** ******** *** ******* ***** in ********* *****/****** ***************.

********* *** *** ******

**** *** ***** **** *******, ** *** *** *** *** software ****** ** ****** *** ***, ***** *****:

Remote *** *******: *** ****** ** ******

*** ********* ***** ************ * ****** *** **** *** ****** VPN, ********** * ****** ******* ** ****** ******(*). ** *** example *****, ******* *** *********** **** *** *** ** ************, but **** ****** **** *** ********** ** ***********, **** **** video ******* ** **** * *** *******.

Remote *** *******: ****** ****** ** ******

****/**** **** *** ** **** ** ****** ******* ** ******** to ********/******** *******. *** *******, *** ***** ***** ***** ***** Mobile ******* ** ** ******, ********* ** * ****** ****** via *** ********* ****** ******* ***. *** ****** ** ********* in *** *** ***, **** ** *** ****** ******* ******.

***********

***** *** ******** ******* *******(**** ******** *** *********) ***** **** *** ******* ***** ** VPN ********, ** ****** *** ***** ** ****** **** ****** in **** *** ******, ** ** ******** ****** ******** *** accountability **** ***** ****** ****** *******. ***** ****** *** ****** to **** ******** ** ********** ** ***** ******** ****** ******** to ********.

Comments (22)

**** ****, **** ****!

* ****, ***** ** *** *********. ***** *** ***** **** issues ** ******** *** ******** ******* **** ** ********* ******* connections *** **** ** **** **** * **** ** *** right *********.

**** *** ****!

**********, *** *********... ****** ****'* ****** ** ***...

**, ******* ***** **** ***** *** * *** ** ****** at **** ** ****. **** ****** **** ****** ** ******* in *** ****** **** ********** *******, ** ** **** **** other ******, *** ** ****** ** *** *** ****** ******* first.

*** ******!

**** ** * ******* ******* *** ***** *** ******* *** first ***. *** ***** ** ** **** ***'* **** ***** control ** *** *******, ** *** ***** ***, * ***** be ********** ** ****** **** ********* ******** ***** ******** ** VPN **** ****** ********. ** ********* *** ******* *** ** based *** *******, *** *** ***/*** *******, ** ***** ** nice ** **** ********* ** ***** *** ** **** *** access **** ** ** *** **** * ** ** ***** hop *******.

*** ***** **** ** **** ** *******. ***** ********* **** on *** ** *** ******* ******** *********.

***** **** * ***** ****** **** ****** ********. * *** do **** **** * **-*** ** ****** ***** ****** *** OpenVPN.

*******, * ***'* ****/**** ******* *** ******. * ****** **** a ********* **** **** **** ** * *** *******. *********, a ******* ******* ** *** *******.

****, *** ******* *** ***** ************. **** ***'* **** *** VPN **********, *** *** ******* *** **** "****** ******** *** throughput (** ** ** **/*)", ***** ***** ** ** ****** that *** *** ** ***** **** *******. ****/* ***'* ****** to ***** ****** ******* ** **** **** ** ****** *******. However, *** **** ***** **** **** ** ****** ******** ****** than **** *******, ** **** *** *** ****** ******.

***** *** **, **** ****** **** *****/*** (***).

*******, ******** ** ********* ******** (*******) ** ***** *** ********** you ****. **** **** ********* ****** ********* ** ****** ******* config ***** *** **** *******. **** *** **** *** ** permanent ****** ** ****** ***********. **** **** **** **** ** routers *** ******** ***** ***** *********** *** *** *********** ***** subnets *** ** *********.

*** ****** **** * **** *******://***.******.***** ***** **** *** ********* ********* ** ** * ****** of ***** ***** * **** **** * *** *** ** other ******. **** **** * *** ****** *** ***'* *** the ********, ** * **** ** **** *** *************. *** can **** *** **** ****** ********** ** **** **** ******* or ****** ******.

* *****, ** *******. * **** ********* **'* *** *** underpowered *** ****. ***** *** ****.***. ******-***** ********* ***** **** some ****** **** *****. ** *** ************* **** **** ***, we *** ******* *** ** **** ********** *** *** ****** airport *******. ** *** ******* *** ******* ** * ***** intranet **** *** ****, ****** ****** **(*****) *** ** *** into *** **** ** ********* *** ******** ** *** *******. The ****** ***/** ****** ******/**** **** ** ******* ** * remote *** ****** *** * *** ***** ***** *** **** so ***** ** ***** *** ****** ** ****** ****** ** the ***** ****** *******. **** ** .**.

***** * *** *** ******** ********** **** ********* ******* ** and ********** **** ***** ***, ***** **** ***** ** **** as **** ******* *** **** ************* ******* ***.

**** *** ******* **** ***** **** * ****** ******* - Amcrest (*****) ****** $** ** **** ******. ***** **** *** the *********** **** ****** ************* **** ****** **** **. *** two ** *** *** ****** **********.

*** ** *** ** *** ***'* ******** *** ******* ** a **** ** ***** ********** ******* **** ******* ***, **** device ***** ***** ** * *******...

** ** ****, **** ****** *** ******** ** **** ***** storage ******** ** *******, *******, *** ** *** *** ** was *** **********, *** *******.

**** ******* ****** ** **** **** **** *** *** ******'*.

Facebook? Really!

***** **** **** *** **** ********, **'* **** ** ********* the ****** *** ** *** ******** ******** *******. ***** *** many **** ** ** ****. *** *** ****** *** **** the *** ******* * ******* (**********). *** *** ***** *** traffic *** ******** *****. *'* **** ***** *** *****, **** complicated ****, *** ***** *** *** ****** ****.

** ** **** **** ** **** **** ******** *******, ****** than *********** * *** ** ****, *** ** *** *** done, **** *'* **** ****** * *** ** *** ****** protection ** ******.

**** ****** **** ** ******** ********** ** * ******** ***** IP, ** ** **** ** **** ********* **** * ******* entity ****** **** ** ****** *** ***** ** *** * botnet.

**** *******, *** ******* *** ** *** *** *********, *** worse *** **** ********** *********** ***'** ***. ***'* ****** **** from *** ***** ***** $***. ***** *** ** ********** ** the ****, *** *** ****. *** **** ******** *******, **** when ***'** ******* **** ******** ******** **** ********* *** *********, when ***** **** ** **** **'* **** ** **** *** brands *** ****.

* *** ******* *** **** ** ******* ***** * **** a **. ** ** *** **-**** ******** **** * **** a *****, *********** **** **** ***** *** *******/*******, ** ***** a *** *** ****** **** *** ***.

*****'* **** *** **** ****** "*********" ******* ** ******* ***** is, ** ******, ****.

**** ** ** ********* *******.

* ***** *** **** ****** ********* ***** **** *** **** across * ***. ** **** *** ** ************* **** ********* listens *** * ******'* ********* (*******, *****, ********) ** **** not ******** *** ****** ** ********** ** *** ******** * VPN. ********** ****, *******, ******* ******** * **** (******* ***) which ** * ********* ***** **** * ***. **** ** to *** **** **** ******** ********* ** *** **** ****** as *** ****** *** *** ** *** ** *** ************* ******, *** * ******* ********** *** **** ***** **. ** always, ***** *** ******** ******** *** ******* **** ***** ***** broadcasts ****** **** * ****.

**** **** ****, **** ****** ************* **** ************* ***** **** actively "****" ** ** ***** *** *** ******** ******* ****** a ***. * ** ***** ** ******* *** ****, *** I ** **** ***** *** ****. *** ** **** ** specify ** ** *****; *** ****** **** ************ **** *.*.*.*.* to ***.***.***.***. ****, * ******* *** *****, *** ** ***** take * ****, **** **** ****. *** ***** ***** **** is ****** ** ********, *** * **** ******* **** *** provide **** *******.

*** ** **** *********? ******* *** **** * ****** **** many, **** ****** ********* -- ******, ******* -- **** **** store ** * ********* ******. **** ******** ******** * *** to ***** *******. *** ** *** ******** *** *******/********* * particular *****'* *******, ******* ******* **** **** *** ************?

** **** ********, ******'* *** **** ** *** ** ****** at ***** ******** *******? *** ***** **** ** ***** *** VPN *** ****** ****** ** *** ********* ******?

*****, ******-********* ******* *** ********** ** *** ******** ******. ** they *** *** ******** ** *** ********, *** ****** *** connectivity ** *** ****. *******, *** ********** *** ** ****** to ***** ****** ******* *** *** * ****** ** *** in * ****** ********.

***** ******* ****. *'* ** ********** ** *** **** **** of *********** *** *** **** ******* ***** **** *** ***. Any ********** ******* ** ******* ******?

**** *** ***

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Related Reports on Access Control

Access Control Course Winter 2018 on Jun 11, 2017
The Winter 2018 IPVM Access Control Course is now open; save $50 on early registration. IPVM offers the most comprehensive access control course...
RMR Integrator Importance Statistics on Jun 08, 2017
How do integrators feel about offering RMR / recurring revenue services? For many, their business revolves around RMR, while others see no...
HID Edge EVO Tested on Jun 07, 2017
HID Edge controllers have been one of most common offerings in IP door controllers for years. The new generation is called Edge EVO. We tested...
Access Control AHJ Nightmares on Jun 01, 2017
For access control jobs, a single person can be the difference between finishing a job, costing thousands in extra dollars, and being profitable...
US States Security Licensing Guide on May 30, 2017
In the US, many states require integrators to be licensed to install burglar alarms, CCTV, electronic access control, or all three, and...
Anti-Hack Access Card Shields Tested on May 26, 2017
Keeping your access control card information secure is becoming a big priority, especially since cheaper copiers can hack details easily. Multiple...
Hackable 125kHz Access Control Migration Guide on May 19, 2017
Despite being one of the most popular credentials, 125 kHz credentials are easily copied and insecure as we showed in our test results, video...
Smartphone Controlled Kevo Lock Tested on May 04, 2017
Smartlocks are a growing market, with millions sold. Kwikset's Kevo is one of the most common choices, using the Unikey smart phone access control...
Hack Your Access Control With This $30 HID 125kHz Card Copier on May 01, 2017
You might have heard the stories or seen the YouTube videos of random people hacking electronic access control systems. The tools that claim to do...
IPVM First Dean's List W2017 - Thomas Atkinson, Matt Hurly and Fredrik Lundqvist on Apr 24, 2017
IPVM is happy to congratulate and celebrate our first "Dean's List", the top students in our courses. For the Winter 2017 IP Networking course...

Most Recent Industry Reports

Uniview Low-Cost Bullet PTZ Tested on Jun 21, 2017
Uniview is offering a HD zoom bullet camera, the IPC742SR9-PZ30-32G, with an integrated pan / tilt positioner, for the price of a low-cost...
QSR Video Surveillance Best Practices on Jun 21, 2017
Fast food restaurants or QSRs (quick service restaurants), are frequent victims of crime and fraud. Because they are open late, deal with cash, and...
45 Drives 'Lowest Cost' Enterprise Storage Company Profile on Jun 21, 2017
45 Drives claims the "lowest cost per Hard Drive Slot in the industry." But who or what is '45 Drives'? What started as a product design to...
No Hack, Still Liable, Court Finds ADT on Jun 20, 2017
Recently, ADT has been in the news for a $16 million settlement for a cyber security vulnerability class action suit. One of the most important...
Resolver / PPM 2000 Incident Management Platform Profile on Jun 20, 2017
You might have seen the company whose employees wear hockey jerseys at trade shows and wondered "what do they do?" PPM 2000 has been active in...
Axis P3225 Mk II Tested Vs. Original on Jun 20, 2017
Axis has released a number of 'Mk II' versions of their cameras, which are the same fundamental camera but with specific improvements. We tested...
Directory of 40 IP Camera Manufacturer Discovery Tools on Jun 19, 2017
Locating the IP address of a DHCP client or factory defaulted device on a network is often a difficult task.  In another report, we discussed...
Dahua Demotes USA CEO on Jun 19, 2017
Dahua has demoted their USA CEO Tim Wang. Inside this note, we examine the move, Dahua's challenges and what lies ahead for the...
Avigilon Increases Prices In Canada, Europe and UK on Jun 19, 2017
While many video surveillance companies are racing to see who can cut prices the fastest, Avigilon is taking a contrary approach, actually raising...
VMS UI - Light vs Dark Preferences on Jun 16, 2017
Several VMS manufacturers have the ability to choose a user interface with either a light or dark color theme. 150+ integrators told us which they...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact