How to Block Security Cameras from the Internet (Firewall & NTP Guide)
To stop PoE and WiFi security cameras (Hikvision, Dahua, Amcrest, Reolink, Lorex) from phoning home to overseas cloud servers while keeping local NVR recording and accurate video timestamps intact, assign your cameras static DHCP reservations in a dedicated IP range (192.168.1.200–230) or Camera VLAN, create a WAN Outbound Drop firewall rule, and redirect UDP Port 123 (NTP) to your local router.
- Why Cameras Phone Home: Even with P2P/UID disabled in the camera web GUI, many IP cameras continuously ping external STUN/UDP cloud servers (`p2p.reolink.com`, `ezvizlife.com`) every 30 seconds.
- Group Cameras in a CIDR Block or VLAN: Assign cameras static DHCP leases in a clean `/27` block (
192.168.1.192/27= `.193–.222`) or an isolated Camera VLAN (`VLAN 30`). - Block Both IPv4 & IPv6 WAN Outbound: Create a
LAN-to-WAN Drop/Rejectrule for your camera IP group—and disable IPv6 on the Camera VLAN so cameras can't bypass IPv4 rules via SLAAC. - The Local NTP Secret (`UDP Port 123`): Cameras blocked from the internet lose their clock drift and some Reolink/Dahua firmwares reboot every 24 hours if NTP fails; point camera NTP to
192.168.1.1!
Why PoE and WiFi Security Cameras Must Never Touch the Public Internet
Hardwired PoE security cameras from Hikvision, Dahua, EmpireTech, Amcrest, Lorex, and Reolink offer vastly superior optical sensor quality and local 24/7 RTSP/ONVIF recording compared to cloud-only subscription doorbells and cameras. However, embedded camera firmware runs stripped-down Linux kernels (`BusyBox`) that rarely receive security patches after 18 months and have a long history of critical remote authentication-bypass CVEs (`CVE-2021-36260`, `CVE-2021-33044`) and Mirai botnet recruitment.
Worse, packet captures (`tcpdump` and Wireshark) prove that even when you uncheck "Enable UID / P2P Cloud" inside a camera's web interface, many models still fire outbound UDP hole-punching packets to hard-coded AWS, Alibaba Cloud, or regional STUN servers every 30 to 60 seconds. If a camera only needs to send an `RTSP (TCP/UDP 554)` or `ONVIF (TCP 80/8000)` stream to your local NVR—such as Frigate, Blue Iris, or Synology Surveillance Station—it has zero legitimate reason to communicate with the public internet.
Step 1: Assign Contiguous Static DHCP Reservations or a Camera VLAN
Before writing firewall rules, organize your cameras on the network so a single firewall rule catches all current and future cameras without maintaining 12 separate IP entries:
- Option A — Contiguous Subnet CIDR Range (Flat LAN): If your router or switch does not support 802.1Q VLANs, open your router's LAN > DHCP Server table and assign static IP reservations for all cameras inside a clean CIDR sub-block—such as
192.168.1.192/27, which covers IP addresses192.168.1.193through192.168.1.222(30 hosts). - Option B — Isolated Camera VLAN (`VLAN 30: 192.168.30.0/24`): On Ubiquiti UniFi, MikroTik, TP-Link Omada, or pfSense/OPNsense, assign all PoE camera switch ports to an untagged No-Internet Camera VLAN (`VLAN 30`). Better yet, place a dual-NIC NVR (or tagged VLAN interface on your Synology/Proxmox host) directly inside `VLAN 30` so 24/7 4K camera streams never even cross your router's CPU!
Step 2: Create the WAN Outbound Drop Rule (ASUS, UniFi, MikroTik, pfSense)
Do not rely on changing the camera's Default Gateway to a fake IP like `0.0.0.0`—smart malware can easily ARP-scan your subnet to discover your real router at `.1`. Instead, block the cameras at the router firewall:
- Ubiquiti UniFi (Network 8.x/9.x): Go to Settings > Security > Traffic & Firewall Rules > Simple, click Create Entry, set Action: Block, Category: Internet, Source: Camera VLAN (or Camera IP Group), and save.
- ASUS Routers (ASUSWRT): Go to Firewall > Network Services Filter, enable the filter, set Filter Table Type to
Black List, and add Source IP192.168.1.192/27(or individual camera IPs) with Port Range `1:65535` for both `TCP` and `UDP` active 24/7. Alternatively, toggle Block Internet Access directly on each camera icon in the Network Map > Client List. - MikroTik RouterOS / pfSense: Add a forward filter rule: `/ip firewall filter add chain=forward src-address=192.168.1.192/27 out-interface-list=WAN action=reject reject-with=icmp-net-prohibited` (and repeat in `/ipv6 firewall filter`!).
Step 3: Fix Camera Clock Drift & Boot Loops with Local NTP (UDP Port 123)
Here is the #1 mistake users make when blocking IP cameras from the internet: security cameras lack high-precision real-time clock crystals, and without Network Time Protocol (NTP on UDP Port 123), their on-screen video timestamps drift by 2 to 10 minutes per month. Even worse, certain Reolink, Dahua, and Amcrest firmwares interpret failed DNS/NTP pings to `time.windows.com` or `pool.ntp.org` as a frozen network stack and automatically reboot the camera mid-recording!
Fix this permanently in two steps: First, enable the Local NTP Server service on your router (built into UniFi, pfSense/OPNsense, MikroTik `/system ntp server set enabled=yes`, Synology DSM `Control Panel > Regional Options > NTP Service`, or ASUSWRT-Merlin). Second, log into each camera's web GUI under System > Time / NTP and set the NTP Server IP to your router's local address (192.168.1.1 or 192.168.30.1). You can also add a firewall DNAT rule redirecting any camera `UDP 123` packet straight to `192.168.1.1:123`.
IP Camera Local-Only Network Ports & Firewall Rule Matrix
| Traffic Type / Protocol | Port & Transport | Source -> Destination | Recommended Firewall Action |
|---|---|---|---|
| P2P Cloud / Telemetry / STUN | Any TCP/UDP (1–65535) | Camera VLAN/IPs -> WAN Internet | REJECT / DROP (IPv4 & IPv6) |
| RTSP Video & Audio Stream | TCP/UDP 554 | NVR (Frigate/Blue Iris) -> Camera IPs | ALLOW (Local LAN or NVR-to-Camera VLAN) |
| ONVIF Discovery & PTZ Control | TCP 80, 8000, 8899 / UDP 3702 | NVR -> Camera IPs | ALLOW (NVR host only) |
| Network Time Sync (NTP) | UDP 123 | Camera IPs -> Local Router (192.168.x.1) | ALLOW / DNAT Redirect to Router Local NTP |
| Camera Web Admin GUI | TCP 80 / 443 | Admin Workstation -> Camera IPs | ALLOW from Admin PC only; BLOCK from Guest/IoT |
| Unsolicited Camera -> Main LAN | Any TCP/UDP | Camera VLAN -> Main LAN (192.168.1.0/24) | DROP (Allow Established/Related replies only) |
Offline IP Security Camera Hardening Checklist
- Disable UPnP on your router and uncheck 'Enable UID / P2P / Cloud' and 'Auto Firmware Check' inside each camera's web settings.
- Assign all cameras static DHCP reservations inside a contiguous CIDR block (such as 192.168.1.192/27) or an isolated Camera VLAN.
- Disable IPv6 (SLAAC/DHCPv6) on the Camera VLAN or add an explicit IPv6 WAN Outbound Drop rule alongside your IPv4 rule.
- Configure a router Firewall Forward rule set to REJECT (or DROP) all traffic from the Camera IP group to the WAN interface.
- Enable your router or NAS local NTP server and set every camera's NTP server address to 192.168.1.1 (UDP Port 123) so video timestamps stay accurate.
- Access your NVR remotely using WireGuard, Tailscale, or Home Assistant rather than forwarding RTSP or HTTP ports on your router.
Frequently Asked Questions
Should my router firewall rule DROP or REJECT outbound internet packets from cameras?
For outbound LAN-to-WAN blocks on internal cameras, REJECT (which immediately returns an ICMP Destination Unreachable or TCP RST packet to the camera) is often better than silent DROP. When a camera's cloud daemon gets an instant ICMP reject, it stops waiting for a 30-second socket timeout, reducing camera CPU load and preventing web UI sluggishness.
If I block my Reolink or Amcrest cameras from the internet, can I still view them on my phone away from home?
Yes! Connect your phone to your home router's WireGuard VPN or Tailscale subnet router; once connected, the official Reolink/Amcrest app (when added by local IP address rather than P2P UID) or your NVR app (Frigate, Home Assistant, Blue Iris, Synology DS cam) streams live video directly from your home with zero third-party cloud access.
Why can my cameras still reach the internet after I blocked their IPv4 addresses?
If your ISP enables native IPv6 (like Comcast, AT&T Fiber, or Spectrum), your cameras likely auto-configured a global 2001:/2600: IPv6 address via SLAAC and are phoning home over IPv6, completely bypassing your IPv4 firewall rules. Disable IPv6 on the Camera VLAN or add an IPv6 forward drop rule for the cameras' MAC addresses.
Do I need a firewall rule if I just leave the Default Gateway blank in the camera settings?
Yes, you still need a router firewall rule. Leaving the default gateway blank or setting it to an unused IP only stops routine OS routing; if a camera is compromised through an NVR vulnerability or malicious firmware, an attacker can manually add the `.1` gateway route in memory unless your router firewall actively drops the camera's source IP and MAC.
Related Home Network Security & Engineering Guides
- Router Default Password Safety & Credential Hardening — Eliminate default router credentials before botnets hijack your gateway. Separate admin passwords from WiFi WPA3 keys and enforce LAN HTTPS management.
- Router Firewall Settings Explained (SPI, NAT & Rules) — Master your router firewall settings. Configure Stateful Packet Inspection (SPI), disable broken SIP ALG for VoIP, block WAN pings, and secure IPv6 rules.
- How to Secure Smart Home & IoT Devices on Your Network — Isolate untrusted smart TVs, cameras, and plugs on a dedicated IoT WiFi VLAN. Enable mDNS UDP 5353 reflection for AirPlay and block risky WAN callbacks.
- UPS Battery Backup for Router, Modem & ONT Guide — Keep your fiber ONT, cable modem, WiFi router, and PoE switch online during blackouts. Calculate VA runtime, compare sine wave UPS units, and test failover.