Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


Yorkshirekid

193 posts

Master Geek
+1 received by user: 10


#274571 29-Aug-2020 10:53
Send private message

I've discovered today that I've done a stupid thing. I've just installed a surveillance system and found I couldn't see it online. Then I learned that wirless modems can get multiple IP addresses per day, which is why I couldn't connect as the dam thing was changing addresses all the time.

 

No problem, I thought, I'll just ask for a static address. I was told by the telco that static isn't possible on a wirless modem. The only solution is to have fibre to the door.

 

So, I thought I'd ask here, to see if there is any other workaround members may have an idea of please?





[IF YOU DON'T KNOW, YOU DON'T KNOW]


Create new topic
sbiddle
30853 posts

Uber Geek
+1 received by user: 9996

Retired Mod
Trusted
Biddle Corp
Lifetime subscriber

  #2551829 29-Aug-2020 10:56
Send private message

Who is your provider? 50+ sell wireless connections in NZ.

 

You don't need a static IP to access a remote system, solutions such as dyndns solve this very easily.

 

The bigger issue is that I assume you are using a port forward to access your camera system. If you are you should immediately disable this and should not be using this under any circumstances. It is an incredibly insecure setup.

 

 




Yorkshirekid

193 posts

Master Geek
+1 received by user: 10


  #2551837 29-Aug-2020 11:02
Send private message

Thanks Steve - Vodafone is the provider. And yes, I did set up port forward.

 

I'm reading up on what dyndns is now..............

 

 

 

 





[IF YOU DON'T KNOW, YOU DON'T KNOW]


Spyware
3818 posts

Uber Geek
+1 received by user: 1366

Lifetime subscriber

  #2551845 29-Aug-2020 11:10
Send private message

More likely that connection is CG-NAT so port forwarding won't work.





Spark Max Fibre using Mikrotik CCR1009-8G-1S-1S+, CRS125-24G-1S, Unifi UAP, U6-Pro, UAP-AC-M-Pro, Apple TV 4K (2022), Apple TV 4K (2017), iPad Air 1st gen, iPad Air 4th gen, iPhone 13, SkyNZ3151 (the white box). If it doesn't move then it's data cabled.




freitasm
BDFL - Memuneh
80660 posts

Uber Geek
+1 received by user: 41077

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2551862 29-Aug-2020 11:29
Send private message

Yorkshirekid:

 

Thanks Steve - Vodafone is the provider. And yes, I did set up port forward.

 

 

In which case you just opened your internal network to all sorts of nasty security risks.

 

Do yourself a favour and disable port forward. If you want access to your cameras you have two options:

 

1. Use a system that does not need port forward

 

2. Investigate a VPN setup and connect to your network via VPN when needed. 





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


Yorkshirekid

193 posts

Master Geek
+1 received by user: 10


  #2551868 29-Aug-2020 11:34
Send private message

Thank you - but it DID work when I first configured it. But later in the day it failed and I found I couldn't ping the IP.

 

I had no idea that wireless modems changed their address a few times a day (a techie friend told me this), so when I went onsite I discoverd it had.

 

So I'm just getting my head around EZDDNS, which is what this system uses and hope this will work.

 

I'm not in the tech industry so learning stuff as I go.

 

Question - can I establish a VPN if I have a wirless modem?

 

If the answer is 'no', then what do I need to do to make this so (said Picard), without having to change the plan to fibre, which would invovle me having the telco come along and install a fibre line to the premises.





[IF YOU DON'T KNOW, YOU DON'T KNOW]


RunningMan
9189 posts

Uber Geek
+1 received by user: 4842


  #2551872 29-Aug-2020 11:43
Send private message

You're missing the main point. It doesn't matter whether you have a static or dynamic IP or use DynDNS or something similar. If you have a system that has to port forward it is a massive security risk. You will end up as part of a DDoS attack on NZX or similar. Stop reading about DynDNS and look at the dangers of port forwarding and how insecure it is.


 
 
 
 

Shop now for Lego sets and other gifts (affiliate link).
freitasm
BDFL - Memuneh
80660 posts

Uber Geek
+1 received by user: 41077

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2551875 29-Aug-2020 11:46
Send private message

@Yorkshirekid:

 

Question - can I establish a VPN if I have a wirless modem?

 

If the answer is 'no', then what do I need to do to make this so (said Picard), without having to change the plan to fibre, which would invovle me having the telco come along and install a fibre line to the premises.

 

 

You can if you have a static IP address.

 

But no port forwards. Ever.





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


Spyware
3818 posts

Uber Geek
+1 received by user: 1366

Lifetime subscriber

  #2551876 29-Aug-2020 11:47
Send private message

Yorkshirekid:

 

If the answer is 'no', then what do I need to do to make this so (said Picard), without having to change the plan to fibre, which would invovle me having the telco come along and install a fibre line to the premises.

 

 

You can run a VPN client on another router, e.g., a Mikrotik, or any linux box, and point to VPN server in cloud or anywhere.





Spark Max Fibre using Mikrotik CCR1009-8G-1S-1S+, CRS125-24G-1S, Unifi UAP, U6-Pro, UAP-AC-M-Pro, Apple TV 4K (2022), Apple TV 4K (2017), iPad Air 1st gen, iPad Air 4th gen, iPhone 13, SkyNZ3151 (the white box). If it doesn't move then it's data cabled.


sbiddle
30853 posts

Uber Geek
+1 received by user: 9996

Retired Mod
Trusted
Biddle Corp
Lifetime subscriber

  #2551878 29-Aug-2020 11:54
Send private message

Assuming you just have a Vodafone modem there isn't a lot you can do to securely configure your system without remote access without spending $ on additional hardware. The connection and camera hardware you've chosen for your solution isn't really the ideal solution for your requirements.

 

I also thought all Vodafone FWA and RBI was CG-NAT so am surprised it could ever work.

 

 

 

 

 

 


Yorkshirekid

193 posts

Master Geek
+1 received by user: 10


  #2551883 29-Aug-2020 12:13
Send private message

Ok thanks all. It’s so disheartening to be told I’m not getting the point (when I do), that I’ve done it all wrong and that I shouldn’t have started in the first place. I don’t like being bullied. I’m sure the people that DDOS NZX don’t care about a small church but I do want to make it secure in case they happen to come along.

 

Thank you spyware for offering a solution but I don’t understand what you’ve said, sorry. I’m out of my depth and the time I have to watch youtube to get up to speed.

 

I’ve put literally hours in over the last 4 weeks drilling holes, running cable, getting cobwebs in my hair, home testing…… as I set it all up. All in my spare time. I’m learning as I go and I had no clue of this latest hitch. I’m trying my best.

 

This morning I went to Mitre10 to get a part to fix the shower. An assistant told me I was getting the wrong thing and gave me a solution. THAT was helpful. ATM I have no idea why my surveillance hardware is wrong; I just know I've been told it is.

 

I now realise I need to pay somebody to do this job correctly and that there are potential workarounds. I’ve done all the work for free to save the people I’m helping, but now I’m at my limit as I don’t know how….

 

Thank you all





[IF YOU DON'T KNOW, YOU DON'T KNOW]


freitasm
BDFL - Memuneh
80660 posts

Uber Geek
+1 received by user: 41077

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2551885 29-Aug-2020 12:15
Send private message

I am sorry you feel bullied. This is certainly not the intention.

The idea is to implement something secure to avoid headaches in the future - something that can cost more at the end.




Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.