Jump to content

Recommended Posts

Posted
That's easy, it's more them being used to hack into the network because of bugs/having to be removed from the network because no one bothered to fix the bugs/not getting features that we require in the future that could just be software updates

 

Or you risk OSS projects stalling as the main developer does something else, meaning no updates.

 

If you VLAN off the devices and restrict access would that be reducing the risk enough? If you are paying a software and support contract on the devices then any bugs they have should be sorted asap.

Posted
Or you risk OSS projects stalling as the main developer does something else, meaning no updates.

 

If you VLAN off the devices and restrict access would that be reducing the risk enough? If you are paying a software and support contract on the devices then any bugs they have should be sorted asap.

 

At least you have options then though, take over/pay someone to take over. Better than paying a support contract as you only maybe have to pay.

 

VLAN isn't perfect, and is annoying, wrt to assigning ports and auditing. Got to make sure everyone's on the right vlan, and the ACLs work. Best we've got unless your cameras support 802.11x I guess

Posted
At least you have options then though, take over/pay someone to take over. Better than paying a support contract as you only maybe have to pay.

 

VLAN isn't perfect, and is annoying, wrt to assigning ports and auditing. Got to make sure everyone's on the right vlan, and the ACLs work. Best we've got unless your cameras support 802.11x I guess

 

At home I have the CCTV traffic vlan routed on the firewall so access is given from there. At work we have much the same setup. CCTV vlan is layer 2 through to a seperate firewall we do not manage and not routed at same switches as normal PC traffic so no ACLs required. Newer Departmental buildings have seperate CCTV networks in there own cab and we do not touch these at all.

 

Yes vlans are some extra admin or as you say you could use 802.1x if the devices support it or assign manually if they don't. I think there is a way to get 802.1x working with non-compliant devices but not done that yet.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...