In any connected video surveillance installation, the same question comes up sooner or later: how do I connect my equipment to the outside world? This usually applies to two scenarios: remote access to cameras or the VMS from outside the local network, and — even more critically — connecting the equipment to the Alarm Receiving Centre (ARC), which needs to receive the events and alarms generated by the installation reliably and continuously.
In both cases the traditional answer has almost always been the same: opening ports on the router or firewall to allow the incoming connection. It’s a solution that works, but it also opens a door — literally — to risks that often go unnoticed until it’s too late.
What does “opening ports” mean, and why is it done?
Opening a port means configuring a network’s router or firewall to allow incoming connections from the internet to a specific device, such as an IP camera, a recorder or a VMS server. It’s the classic way to make a device remotely accessible — or able to communicate with external services such as an ARC — without needing to be physically on the same network.
The problem is that, by doing this, the device stops being “hidden” behind the router and becomes visible — and potentially reachable — from anywhere on the internet.
The main risks of having open ports
Public exposure of the device. An open port turns a camera, recorder or VMS server into a resource visible from the internet at large, not just from authorised personnel. The longer it stays exposed, the wider the risk window, regardless of whether an incident actually occurs.
Unauthorised access. If the device’s credentials are weak, still set to factory defaults, or reused across several devices, an open port makes it easier for someone without authorisation to get into the system.
Dependence on how up to date the device is. Like any software, camera, recorder and VMS platform firmware receives security updates over time. A device that is exposed and not kept up to date is more exposed to having those known weaknesses exploited.
An entry point to the rest of the network. A compromised video surveillance device is rarely the final target. It’s usually the foothold used to reach other systems on the same network: servers, workstations, management systems.
Risk to third parties. A compromised device doesn’t only put its owner at risk: poorly protected cameras and recorders have historically been used to launch attacks on other systems without the owner ever knowing.
Why video surveillance is a particularly attractive target
Unlike a computer or a server, video surveillance devices tend to fly under the IT department’s radar: they’re installed by an integrator, stay in operation for years, and rarely receive firmware updates or periodic security reviews. That combination — exposed to the internet, poorly maintained and with weak credentials — makes them one of the weakest links in any network.
If you can’t avoid opening ports: basic mitigations
When opening ports is unavoidable, there are measures that reduce (though don’t eliminate) the risk:
- Use a VPN instead of exposing the port directly to the internet. It’s one of the most common and effective alternatives, but it’s worth being clear that setting it up and maintaining it isn’t trivial: it requires advanced networking and IT knowledge (managing tunnels, certificates or keys, addressing, clients on each end…), something that isn’t always within reach of a standard installation or the staff who maintain it.
- Restrict access by source IP on the firewall, instead of leaving it open to any IP.
- Change default ports and, above all, factory credentials.
- Keep the firmware up to date on cameras, recorders and VMS.
- Segment the network used for video surveillance from the rest of the corporate infrastructure.
Portless: removing the risk at its root
The most effective alternative isn’t to mitigate the risk of having open ports, but to remove the need to open them in the first place. That’s why DFUSION /3 includes Portless Connectivity: an architecture that establishes the connection with the equipment — for both remote access and communication with the ARC — without needing to open any port on the network or have a static IP.
This means the device is never exposed to the internet: there’s no open port to find or attack directly from outside, because the attack surface simply disappears.
Portless is also fully compatible with restrictive IT policies where opening ports is limited or prohibited, and it works without restrictions even with network providers where configuring this is complex, such as Orange or Starlink.
| With open ports | With Portless | |
|---|---|---|
| Visibility from the internet | The device is publicly exposed | Not exposed, no open port |
| Static IP required | Yes, in most cases | No |
| Compatible with restrictive IT policies | Depends, often not | Yes, always |
| Risk of unauthorised access | High without additional mitigations | Eliminated at the source |
| Setup | Requires networking knowledge (NAT, firewall, VPN) | Simple, no network intervention needed |
| Works with any provider (Orange, Starlink…) | Not always | Yes |
More about Portless Connectivity
Conclusion
Opening ports has for years been the usual way to connect video surveillance equipment to the outside world and to the ARC, but it’s also one of the main sources of security risk. Classic mitigations — starting with VPNs — reduce that risk, but at the cost of a complex setup that requires advanced networking and IT knowledge.
DFUSION /3’s Portless Connectivity solves the problem at its root: it not only removes the need to open ports — and with it the attack surface — but does so without complex configuration or any intervention on the network. Connecting the equipment, both for remote access and for sending alarms to the ARC, is simple, secure and reliable, even in environments with restrictive IT policies or providers where other solutions don’t work.
Frequently asked questions
Is it safe not to open any port to access the cameras or connect to the ARC remotely?
Yes. With a portless architecture like DFUSION /3’s, the connection is established without exposing any port to the internet, which removes the most common exposure vector in video surveillance systems.
Can someone access my cameras if I leave a port open?
It’s a real risk if it isn’t paired with other measures: strong credentials, up-to-date firmware and IP-based access restriction. The longer and the more devices remain exposed, the greater the likelihood of unauthorised access.
Isn’t using a VPN enough?
A VPN is a good mitigation, but it involves complex setup and maintenance that require advanced IT knowledge. Portless achieves the same goal — avoiding exposed ports — without that complexity.
Does Portless replace other security measures such as the firewall?
No, it’s complementary. Portless removes the need to expose ports, but good practices such as network segmentation or firmware updates are still recommended.






