Hello all,
at my home, I'm connected to a W-ISP via theirs WiFi as a client. This represents WAN for me, and as such it is connected to RBhEX WAN input,
while the rest of the RBhEX eth. ports are connected to a local LAN devices (computers, wifi AP, and such stuf, with the obvious NAT and Firewall setup).
The "issue" which I would like the experienced people in here to help me out with, is:
how to connect the linux-based DVR (NVR) box which is "made in china", and which is obviously absolutely not to be trusted (could be hacked due to a poor design, or already might contain a malicious firmware or hidden linux applications that would probe my network or send video data to someone else, and such).
I do have a friend doing a maintenance on Huawei kits for mobile operators, and what he showed me is terrifying (the devices stream all the data to china, continously, and the worst part is that all the O&M has to go through Huawei HQ, so if you want to change a configuration, you have to call them, and they do it remotely from china, brrr....).
I'm quite sure that basically any other device (as the DVR is) would eventually do the same, just run the wireshark and watch.
So back to the topic:
I'm looking at the NVR4108-8P-4KS2 box (see the PDF, first link found on google: http://www.cctvcentersl.es/upload/Catal ... P-4KS2.pdf and on many other places through inet).
The beautiful thing about this box is, that it contains its own, physically separate PoE switch, for all the IP cameras connection - so I do not have to connect the cameras through any outside switch.
Beside the cyber security risk, such a DVR box is quite a great solution for a reasonable price (in fact, should Mikrotik build their own, I will buy it right away much rather than something from a chinese company).
Now, to the question itself:
How to properly isolate the DVR from the internal network (house LAN) and from the Internet (WAN), while allowing for the remote access (using a mobile application to view the DVR output).
I'd like to have that one RBhEX ethernet port connected to the DVR box - to be extra firewalled (limited), while the rest of the RBhEX ports will stay generic and with a default (yet secure) set of firewall rules. Is this even possible with the RBhEX hardware, and if yes, then how.
Or in general, does anyone have any further tips on how to set the whole thing up, and how to properly secure it, would be more than welcome.
I would suppose that many people are connecting such chinese boxes, and are not actually worried about the "trojan horse" these boxes do represent.
So any proper guidance would be more than welcome, for sure on my side it will.
Also, are there any greylist/backlist lists of IP addresses, which are somewhat "official" and could be somehow downloaded to RBhEX, so it will block the outgoing LAN traffic (e.g. blocking any internal on-LAN device to open a UDP/TCP connection to WAN, if the target IP is blacklisted). Also, does RBhEX firewall block things such as "ping tunnel" or non-udp/non-tcp malicious traffic (LAN to WAN)?
thank you,
a.