0

No products in the cart.

Trade Login

CCTV Remote Viewing Configuration

Knowledge Base › CCTV  ·  Last reviewed September 2026  ·  Connixtech technical team

Remote viewing means reaching an NVR from outside the site network. If you have not commissioned the recorder yet, start with the NVR Setup Guide. There are three practical methods and they differ enormously in security.

Short answer: P2P cloud for most sites, VPN where the client has IT policy or higher security requirements, and do not use port forwarding.

The three methods compared

Comparison of P2P cloud, VPN and port forwarding methods for reaching an NVR remotely
P2P and VPN both keep the recorder unreachable from the open internet. Port forwarding publishes it.
MethodSecurityNeeds public IPBest for
P2P / cloudGood with 2FANoMost residential and SME
VPN to the siteBestYes, or cloud VPNCorporate, multi-site
Port forwardingPoorYesNot recommended

Why port forwarding is not recommended

Forwarding a port to a recorder publishes it to the entire internet. Recorders and cameras are scanned continuously, weak credentials are brute-forced within hours, and known firmware vulnerabilities are exploited automatically. Compromised recorders have been used at scale for botnets and for lateral movement into the business network they sit on.

If a client insists: change the default port, use a long unique password, restrict source IPs at the firewall, keep firmware current, and isolate the recorder on its own VLAN. Better — use one of the other two methods.

Method 1 — P2P cloud

P2P works by having the recorder make an outbound connection to the manufacturer’s servers. The app connects to the same servers and the two are introduced. Because both ends dial out, the firewall never needs an inbound rule — which is also why this is the only one of the three methods that survives CGNAT.

  1. On the recorder, enable the platform access / P2P service.
  2. Set a verification code — change it from the default. This is what protects the stream.
  3. Confirm status shows “Online”. If offline, check the recorder’s gateway and DNS, and that outbound internet is not blocked.
  4. Install the app: Hik-Connect (Hikvision/HiLook), DMSS (Dahua), or the manufacturer’s app for other brands.
  5. Create the client’s own account, not yours. The client must own the account or they cannot manage access after you leave.
  6. Add the device by QR code or serial number.
  7. Enable two-factor authentication.
  8. Test on mobile data with the phone off site Wi-Fi. Testing on site Wi-Fi proves nothing — it may be connecting locally.

Requirements: working outbound internet, correct DNS, and correct time. A recorder whose clock is badly wrong will often fail to establish a cloud connection.

Method 2 — VPN

A VPN puts the remote device onto the site network, so the recorder is reached at its local IP. Nothing is exposed to the internet.

  • Configure the VPN server on the site router or firewall — WireGuard and OpenVPN are common, and many business routers include one
  • Give the client’s device a VPN profile
  • In the app, add the recorder by its local IP address
  • Connect the VPN first, then open the app

This is the right answer for any site with an IT department. Trade-offs: setup complexity, a router capable of it, and a client who will actually connect the VPN before viewing. Routers: Wi-Fi Routers. Switches and PoE: PoE Switches.

CGNAT: check this before you troubleshoot anything

Under CGNAT (carrier-grade NAT), multiple customers share one public IPv4 address. The site has no public IP of its own, so port forwarding and DDNS cannot work — no matter how the router is configured.

How to test for it — two minutes

  1. Open the router’s status page and note the WAN IP address
  2. On a device on that connection, check an external “what is my IP” lookup
  3. If the two differ, the connection is behind CGNAT

A WAN address in the 100.64.0.0/10 range — anything from 100.64.x.x to 100.127.x.x — is a direct indicator. Addresses in 10.x, 172.16–31.x or 192.168.x on the WAN interface point the same way.

Which New Zealand connections are affected by CGNAT?

CGNAT is a provider decision, not a technology one, so the only reliable answer is to test the specific connection. That said, the pattern we see on NZ sites:

Connection typePublic IP likely?
UFB fibre, business plan with static IPYes — usually a paid option
UFB fibre, consumer planVaries by retailer — test it
Fixed wireless / WISPFrequently behind CGNAT
SatelliteCommonly behind CGNAT by default
Mobile broadband (4G/5G router)Almost always behind CGNAT

Rural sites are the ones that bite you. A farm, orchard or lifestyle block on fixed wireless or satellite is exactly the site where the client most wants remote viewing, and exactly the connection least likely to support port forwarding. Plan for P2P from the quote stage rather than discovering it on commissioning day.

Upload, not download, is your constraint. UFB fibre plans generally have enough upload for multi-camera remote viewing. Rural wireless and satellite often do not, and satellite adds latency on top. Check the actual upload figure before promising smooth live view.

Bullet camera mounted on a stand-off bracket, held clear of a ribbed building facade
The bracket holds the camera clear of the facade. Mounted flush against those fins, the camera’s own IR would bounce straight back into the lens.

Bandwidth planning

StreamTypical bandwidth
Sub stream, single camera0.5–1 Mbps
Main stream 4 MP H.265, single camera~4 Mbps
4-camera multi-view on sub stream2–4 Mbps

Bandwidth demand follows the stream settings you chose at commissioning, and the camera resolution you specified — see CCTV Camera Mounting and Positioning for how resolution and scene width interact. Configure apps to use the sub stream for live multi-view and switch to main stream only for single-camera detail. On a modest upload, main-stream multi-view will not work regardless of settings.

Fault-finding

SymptomFirst checks
Device offline in the appDNS and gateway; outbound blocked; clock wrong
Works on site Wi-Fi, not mobile dataConnecting locally — P2P is not working
Live view connects then dropsUpload bandwidth exhausted; try sub stream
“Incorrect verification code”Code changed on the device, or still default
Nothing works after an ISP changeRules lost, or moved to CGNAT
Client cannot add deviceStill bound to the installer’s account

Unbind the device from your own account before you leave site. A device registered to an installer account cannot be added by the client, and this generates a support call on every job.

Handover checklist

  • Account in the client’s name, with the client’s email
  • Two-factor authentication enabled
  • Verification code changed from default and recorded
  • Device not bound to the installer’s account
  • Tested from outside the site network on mobile data
  • Client shown live view, playback, search and export on their own device
  • Sub stream set as default for multi-view
  • Firmware current
  • No unnecessary ports forwarded

Planning remote access for a site? Connixtech’s technical team is available Monday–Friday, 8am–5pm NZT. Email info@connixtech.co.nz or call +64 27 284 7161.

CGNAT detection method and address ranges verified September 2026. The connection-type table reflects field experience, not published provider data — CGNAT policy varies by retailer and changes without notice. Always test the specific connection.