Add a password

Port Forward a HikVision DVR/NVR

This article was published in 2021 and has not been revised since. Prices, firmware and model availability will have moved on.

Hikvision recorders use three ports for remote access. Port 8000 carries the control channel that the app uses to log in and issue commands, port 554 carries the RTSP video stream, and port 80 serves the web interface. Forward the first two and the mobile app works. Forward the third as well if you want the browser interface from outside.

Before any of that, read the next section. It is the part most guides leave out and it has cost people their entire camera system.

Read this before you open a port

Forwarding a port puts the recorder’s own software directly in front of the internet, and Hikvision’s software has been compromised at scale more than once.

In 2017, an authentication flaw let anyone pull the full user list and password hashes from an exposed device without logging in. In September 2021, a command injection flaw rated 9.8 out of 10 allowed complete takeover of an unpatched unit with a single crafted request, and mass scanning for vulnerable devices began within days of the advisory. Both were exploited in the wild, and both were exploited specifically against devices somebody had forwarded a port to.

None of which makes port forwarding wrong. It makes it something to do deliberately:

  • Update the firmware first. Not after it is exposed. Before.
  • Change every password on the recorder, including any secondary operator accounts nobody uses. Ours is a directory of default logins and it exists because a great many of these devices are still running the credentials they shipped with.
  • Use non-standard external ports. It stops nothing determined, but it takes you out of the mass scans that sweep for 8000 and 554.
  • Restrict by source IP on the router if it supports it, so only the addresses you use can reach the recorder at all.

If you would rather not expose it, a VPN into your own network gets you the same speed with none of the exposure, and we make the case for that in why not to use cloud DVR access.

The ports, and what each one does

Port Purpose Needed for the app?
8000 Service port. Login, playback control, PTZ commands. Yes
554 RTSP. Carries the video stream itself. Yes
80 HTTP web interface. No
443 HTTPS web interface, where the firmware supports it. No

Forward 8000 and 554 and the app works. Leave 80 closed unless you specifically need the browser interface remotely, and if you do need it, prefer 443 so the session is encrypted.

The mobile app is iVMS-4500, available on the Play Store and the App Store. It connects either directly to a forwarded port or through a Hik-Connect account, which is the cloud route.

Advertisement

Setting up the forward

Give the recorder a static IP first, or a DHCP reservation in the router. A forward pointing at an address the recorder no longer holds is the most common reason this stops working after a power cut.

Router port forwarding table showing ports 8000 and 554 forwarded to a Hikvision DVR at 192.168.0.100

The example above assumes the recorder sits at 192.168.0.100.

The external port does not have to match the internal one, and using a different number outside is a sensible habit. To reach the recorder on 9991 from the internet while it listens on 8000 internally:

External Port Range: 9991-9991
Local Port Range: 8000-8000
Local Address: 192.168.0.100

Connections to your public address on 9991 now arrive at the recorder on 8000. In the app, enter your public address and 9991 as the port.

The recorder’s own port numbers live under Configuration, then Network.

Testing it

Use a service like canyouseeme.org, which detects your public address automatically. Enter the external port number and it will tell you whether something answered.

Test it from outside your own network. A phone on mobile data with Wi-Fi turned off is the quickest way, because many routers will not loop a connection to your own public address back inside, and a failure there means nothing.

If the port shows closed, start with the address. The forward has to point at the IP the recorder currently holds, and if it picked up a different one from DHCP after the last power cut, everything else is wasted effort. Then confirm the recorder is genuinely listening on that internal port rather than the one you assumed.

Carrier-grade NAT is the possibility people miss. Check your public address, and if it begins anywhere from 100.64 to 100.127, your provider has put you behind a shared address. No forward will ever reach you through that. Providers will usually move you to a real public address on request, sometimes for a small monthly charge, and until they do there is nothing to configure on your end that would help.

More than one recorder on the same network

Two recorders cannot both use port 8000 internally if you want to reach both from outside. Give each its own set.

DVR 1
IP: 192.168.0.100 (static)
Service port: 8000
RTSP port: 554
Web port: 80

DVR 2
IP: 192.168.0.101 (static)
Service port: 8001
RTSP port: 1025
Web port: 81

Then forward each pair to the right address. Any port will do as long as it is not reserved and nothing else on the network is using it.

Router port forwarding table with two Hikvision DVRs on separate ports and IP addresses

Add each recorder in the app as a separate device with its own port number.

Common questions

Which ports does a Hikvision DVR need?

8000 for control and 554 for video. Port 80 or 443 only if you want the web interface from outside.

Why can I see my DVR at home but not away from it?

Either the forward is wrong, or you are behind carrier-grade NAT. Check your public address: anything starting 100.64 to 100.127 means the provider is sharing it and no forward will reach you.

Is it safe to port forward a DVR?

Only with current firmware, changed passwords and, ideally, source IP restrictions. Unpatched Hikvision units exposed to the internet have been compromised on a large scale. A VPN avoids the problem entirely.

Do I need a static IP from my provider?

No. A dynamic DNS hostname tracks a changing address, and most routers and Hikvision recorders can update one themselves.

The app connects but there is no video. Why?

Almost always port 554. The control port is working, which is why it logs in, but the stream has nowhere to go.

Advertisement
Facebook
Twitter
LinkedIn
Email
WhatsApp

MORE FROM ROUTERPASSWORDS.COM