Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


sjworthy

7 posts

Wannabe Geek


#293746 11-Feb-2022 11:52
Send private message

Hi All,

 

Any help appreciated.

 

I have a Unifi USG, 2 AP's and 3 switches.

 

All runs well with 3 Vlans. Spent a fair bit of time reading threads and posts on how to set VLans up and the firewall rules. 

 

 

 

Seems to be a bit of confusion (on my end) around the Dahua NVR.

 

I have a rule to block all traffic (Lan_IN) from the VLan the NVR is sitting on, to stop it connecting to the internet, for general security purposes.

 

 

 

Question:

 

1) Can I create a firewall rule to allow only IVS email notifications to get through, and if so, what ports specifically from my NVR? from previous posts I have tried 2195 and 53, but it does not seem to work. I use Microsoft Outlook as the email server in the Dahua settings. I even went in to SSH and looked at the logs when allowing emails to get through (disabling the general 'drop all' rule), but the source ports from the NVR destination always seem to change on each new email that is sent. 

 

2) if this firewall rule is possible, where should it sit on the list?

 

I have:

 

Lan_in -

 

2001 - allow established and related (Before; accept; src is all local ips, dest is all local ips; state estab/related)

 

4000 - drop all Lan3 (CCVT Vlan network) - (after; drop; src is CCTV Vlan; dest is any; no states applied)

 

All other rules are the predefined ones.

 

 

 

I would really like to keep receiving email notifications from IVS alerts, but cant for the life of me figure out how, if at all, this is possible.

 

By having a general 'drop all' traffic to maintain NVR security, this may not even be possible - so if not, it would be good to know either way. 

 

 


Create new topic
davidcole
6034 posts

Uber Geek

Trusted

  #2865377 11-Feb-2022 12:54
Send private message

Think there's another internet port you need, 8888 or something.

 

I don;t have my nvr on a vlan, I just have it in a block insecure from the internet.  And it can only talk on 

 

2195

 

443

 

8888

 

to 170.0.0.0/8

 

 





Previously known as psycik

Home Assistant: Gigabyte AMD A8 Brix, Home Assistant with Aeotech ZWave Controller, Raspberry PI, Wemos D1 Mini, Zwave, Shelly Humidity and Temperature sensors
Media:Chromecast v2, ATV4 4k, ATV4, HDHomeRun Dual
Server
Host Plex Server 3x3TB, 4x4TB using MergerFS, Samsung 850 evo 512 GB SSD, Proxmox Server with 1xW10, 2xUbuntu 22.04 LTS, Backblaze Backups, usenetprime.com fastmail.com Sharesies Trakt.TV Sharesight 




insane
3239 posts

Uber Geek

ID Verified
Trusted

  #2865391 11-Feb-2022 13:15
Send private message

Don't worry about the source ports for outbound connections, those will always be random. You're only interested in the destination ones. Allowing UDP 53 makes sense to allow the DNS lookups to take place, but presumably as David said you'll need to allow more ports to allow the email or event to be dispatched. As you have access to the logs finding that should hopefully be fairly simple if you can trigger one to go out. [sorry not sure whether it communicates via email protocols or sends some event to an hosted service first]

 

 

 

 

 

 


sjworthy

7 posts

Wannabe Geek


  #2866589 11-Feb-2022 18:24
Send private message

davidcole:

 

Think there's another internet port you need, 8888 or something.

 

I don;t have my nvr on a vlan, I just have it in a block insecure from the internet.  And it can only talk on 

 

2195

 

443

 

8888

 

to 170.0.0.0/8

 

 

 

 

 

 

Hi David,

 

Thanks for the reply.

 

Just so I understand this correctly, you open ports 2195, 443, 8888 to 170.0.0.0/8 (what is that range? your usg? or similar, or just a vlan).

 

Do you get any luck opening those ports and receiving emails from IVS notifications or do you not bother with email notifications at all?

 

With those firewall rules you use, do you have them as individual rules or all as a port group in one rule? and do you have any states checked (new, established, related etc).

 

I have tried so many different variations, and still no luck, so really keen to find someone with email notificaitons working, and what specific rules/ports they use and how the rules are specifically set up. 

 

 

 

 

 

 




sjworthy

7 posts

Wannabe Geek


  #2866600 11-Feb-2022 18:38
Send private message

insane:

 

Don't worry about the source ports for outbound connections, those will always be random. You're only interested in the destination ones. Allowing UDP 53 makes sense to allow the DNS lookups to take place, but presumably as David said you'll need to allow more ports to allow the email or event to be dispatched. As you have access to the logs finding that should hopefully be fairly simple if you can trigger one to go out. [sorry not sure whether it communicates via email protocols or sends some event to an hosted service first]

 

 

 

 

 

 

 

 

 

 

Hi insane,

 

Thanks for the reply.

 

There was so much info in the logs I sometimes got a bit lost at what I was looking for. I saw the destination often as 587 (the outlook email port), but have also previously tired opening this port with no luck. Maybe its my firewall rule and how I have set it up that was wrong. 

 

How would you related UDP 53 into a firewall rule to allow email notifications.

 

Would it be Lan in/out/local or on the Wan in/out/local side?


davidcole
6034 posts

Uber Geek

Trusted

  #2866602 11-Feb-2022 18:47
Send private message

I have my nvr blocked from all up addresses on all ports but the 172.0.0.0/8 and those ports listed (i have 25 as well to talk to my smtp servers.

 

Yes I get iOS notifications on the idmss app.  





Previously known as psycik

Home Assistant: Gigabyte AMD A8 Brix, Home Assistant with Aeotech ZWave Controller, Raspberry PI, Wemos D1 Mini, Zwave, Shelly Humidity and Temperature sensors
Media:Chromecast v2, ATV4 4k, ATV4, HDHomeRun Dual
Server
Host Plex Server 3x3TB, 4x4TB using MergerFS, Samsung 850 evo 512 GB SSD, Proxmox Server with 1xW10, 2xUbuntu 22.04 LTS, Backblaze Backups, usenetprime.com fastmail.com Sharesies Trakt.TV Sharesight 


sjworthy

7 posts

Wannabe Geek


  #2866603 11-Feb-2022 18:52
Send private message

davidcole:

 

I have my nvr blocked from all up addresses on all ports but the 172.0.0.0/8 and those ports listed (i have 25 as well to talk to my smtp servers.

 

Yes I get iOS notifications on the idmss app.  

 

 

 

 

Do you VPN from your phone to your network for idmss notifications when away from your home network? or by opening those ports the idmss app works fine with notifications?

 

Sorry if it sounds a bit basic. 


davidcole
6034 posts

Uber Geek

Trusted

  #2866606 11-Feb-2022 18:57
Send private message

sjworthy:

 

davidcole:

 

I have my nvr blocked from all up addresses on all ports but the 172.0.0.0/8 and those ports listed (i have 25 as well to talk to my smtp servers.

 

Yes I get iOS notifications on the idmss app.  

 

 

 

 

Do you VPN from your phone to your network for idmss notifications when away from your home network? or by opening those ports the idmss app works fine with notifications?

 

Sorry if it sounds a bit basic. 

 

 

Vpn yes.    So notification comes all the time.   But if I want the video I have to connect to the vpn to view it.





Previously known as psycik

Home Assistant: Gigabyte AMD A8 Brix, Home Assistant with Aeotech ZWave Controller, Raspberry PI, Wemos D1 Mini, Zwave, Shelly Humidity and Temperature sensors
Media:Chromecast v2, ATV4 4k, ATV4, HDHomeRun Dual
Server
Host Plex Server 3x3TB, 4x4TB using MergerFS, Samsung 850 evo 512 GB SSD, Proxmox Server with 1xW10, 2xUbuntu 22.04 LTS, Backblaze Backups, usenetprime.com fastmail.com Sharesies Trakt.TV Sharesight 


 
 
 
 

Shop now on Samsung phones, tablets, TVs and more (affiliate link).
sjworthy

7 posts

Wannabe Geek


  #2867793 13-Feb-2022 16:47
Send private message

Great, Thanks for the help on this. I will give it a try. 


Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.