A sleek WiFi 6 router with antennas and cable on a wooden desk, perfect for modern home networks.

Port forwarding vs P2P vs cloud relay: why exposing a camera is dangerous

Close-up of colorful love padlocks on a cable, symbolizing eternal love and commitment.
Photo: Wolfgang Vrede / Pexels
In shortThere are three common ways to watch a camera from outside your home or business: port forwarding (opening your router so the internet can reach the camera directly), P2P or cloud relay (the camera connects out to the maker’s service), and a VPN (you join your own network securely). Port forwarding is the risky one, because automated scanners find exposed cameras quickly; for public webcams, pushing the stream out to a platform like YouTube is safest of all.

Most people want to check their camera from their phone. The question is how the video gets from a camera behind your router to a phone on the other side of the world. The answer you choose decides how exposed your camera is, and it is the reason some cameras end up on websites that list unsecured private cameras. LiveLocation is the opposite of those sites: we only show cameras published on purpose. This page explains the options so yours never ends up there.

Why your camera is hidden by default

At home and in most businesses, your router gives every device a private address that only works inside your network. From the outside, the internet sees one public address: the router’s. When a device inside starts a connection to the internet, the router keeps track of it and lets the answer back in. But when someone on the internet tries to start a connection to your camera, the router has no idea which device they mean, and drops it. That behavior, called network address translation (NAT), is a large part of why a camera on a home network is not visible to the world by default.

NAT is not a security feature by design, and it is not a substitute for good passwords and updates, but it does mean nobody can stumble onto your camera unless something opens a path.

Every remote-viewing method is a way around that wall. Some go around it safely; one cuts a hole in it.

Three ways to reach a camera: port forwarding opens a hole for anyone including scanners; cloud relay and push connect outward to a service; VPN lets only your own devices in Who can start a connection to the camera? Port forwarding: anyone Camera Routerport open You Scanners, bots Attackers Inbound from the whole internet: high risk P2P / cloud relay or push: nobody Camera Routerclosed Maker cloud or YouTube (outbound) Camera calls out; trust shifts to the service and your app login VPN: only your devices Camera RouterVPN only Your phone with a VPN key Encrypted tunnel; the camera stays private
The safest designs never let the internet start a connection to your camera.

Option 1: Port forwarding

Port forwarding is a router rule that says: “Anything arriving at my public address on port X, send it to the camera.” It works, which is why old guides recommend it. The problem is that it works for everyone, not just you.

Automated scanners sweep the entire internet constantly, looking for devices that answer on camera ports and web interfaces. Search engines index internet-connected devices by what they reply. A newly exposed camera is typically probed within hours. From there, attackers try default passwords, known firmware flaws and weak logins. The consequences are well documented:

  • In 2013, the FTC settled with camera maker TRENDnet after flaws let anyone with a camera’s internet address view, and sometimes listen to, live feeds; feeds from about 700 cameras were posted online.
  • In 2016, the Mirai botnet took over hundreds of thousands of devices, including network cameras and video recorders, using a list of 62 common default usernames and passwords over Telnet. CISA’s alert advised changing default passwords, updating devices and disabling UPnP.

Even a camera with a strong password is at risk if its firmware has a flaw the attacker knows and you have not patched. Port forwarding turns every future vulnerability into an open invitation.

Check for UPnP. Many routers and cameras support Universal Plug and Play, which lets a device open its own port forwards automatically, without asking you. If you have never set a port forward but your camera is reachable from outside, UPnP is the likely reason. Turn UPnP off in the router unless you know you need it, and turn it off in the camera.

Option 2: P2P and cloud relay

Most consumer cameras today use the maker’s cloud. The camera connects out to the maker’s servers and keeps that connection open. When you open the app, the service either connects your phone and camera directly through the NAT (that is what makers usually call “P2P”) or relays the video through its own servers. No port forwarding needed.

That is much safer than an open port, but it is not risk-free. You are trusting the maker’s servers, software and account security. Protect it by:

  • Using a long, unique password for the camera app account and turning on two-step verification.
  • Keeping the app and camera firmware updated.
  • Choosing makers that publish security updates and say how long they will support a product. UK law (the PSTI regime, in force since April 2024) now requires makers of connected products sold there to state that support period and to stop shipping guessable default passwords.
  • Turning off P2P in the camera if you do not use the maker’s app, for example when it only records to a local recorder.

Option 3: VPN

A VPN (virtual private network) lets your phone or laptop join your home or business network through an encrypted tunnel, as if you were there. Many routers have a VPN server built in, and modern VPN software is easy to set up. Once connected, you open the camera’s own app or interface exactly as you would at home. Nothing about the camera is exposed; only devices with your VPN key can get in. It is the best option for owners who want full control without relying on a camera maker’s cloud.

The trade-offs: a little setup, the VPN itself must be kept updated, and it is for your devices, not for sharing with the public.

Option 4: Push out to a platform (for public webcams)

If you want the public to watch, do not let the public near the camera at all. Have the camera or an encoder push its stream out to YouTube or another platform over RTMPS, and share the platform’s link or embed. Viewers connect to the platform’s servers, never to you. This is how responsible public webcams work, and it is the only kind of stream LiveLocation lists. See RTMP explained and how to stream an IP camera to YouTube.

The options compared

MethodWho can connect to the cameraSetupRisk levelUse it for
Port forwardingAnyone on the internetRouter ruleHighAvoid
UPnP auto-forwardingAnyone, without you knowingAutomaticHighTurn it off
P2P / cloud relayOnly through the maker’s serviceApp pairingLow to medium (depends on the maker)Private viewing on your phone
VPNOnly your authorized devicesSome setupLowPrivate viewing, full control
Push to platform (RTMPS)Nobody; viewers reach the platformEncoder settingsLowPublic webcams

Remote access for businesses and installers

Hotels, ski areas and towns often have an installer who needs to manage cameras remotely. The same rules apply, with a little more structure:

  • Give the installer their own account on the recorder or camera, never the shared admin login, and remove it when the contract ends.
  • Use a VPN or the manufacturer’s managed remote-access service rather than port forwards, and require two-step login where it is offered.
  • Keep cameras on their own network segment (a VLAN), separate from guest Wi-Fi and the office computers.
  • Write it down: which cameras exist, which accounts can reach them, who updates firmware and when. CISA’s guidance on network devices recommends exactly this kind of discipline: change defaults, patch promptly, segment networks and disable unencrypted management protocols.

Questions to ask before buying a camera

A few minutes of research up front can save you from a camera that only works with an open port:

  1. Can I view it remotely without port forwarding (app, cloud relay or VPN)?
  2. Does the app support two-step login?
  3. Can I turn off P2P, UPnP and cloud features I do not use?
  4. How long will the maker provide security updates, and where are they published?
  5. Does the camera force me to set my own password at setup, rather than shipping with a shared default?
  6. For a public webcam: can it push RTMPS, or will I need an encoder?

Our how to choose a live camera guide folds these into the buying decision.

“But I already forwarded a port”

No panic; fix it calmly, in this order:

  1. Remove the port forward (and any DMZ setting) from your router.
  2. Turn off UPnP in the router and the camera.
  3. Update the camera’s firmware from the maker’s official site or app.
  4. Change every password on the camera, the recorder and the app account to long, unique ones, and remove accounts you do not recognize.
  5. Set up a safer method: the maker’s app with two-step login, a VPN, or a push to a platform.
  6. Consider a separate network for cameras so a compromised camera cannot reach your computers. See camera security.

If you think a camera was already accessed by someone else, reset it to factory settings after updating firmware, then set it up fresh.

What about 4G cameras?

Cellular connections usually sit behind the mobile carrier’s own NAT, so port forwarding often does not work at all, and that is a good thing. 4G cameras rely on the maker’s cloud or push their streams out. Avoid paying for a public static IP just to open ports. See 4G/LTE cameras.

Do these next

  1. Log in to your router and check for port forwards and UPnP.
  2. Pick a safe method: app with two-step login, VPN, or push to YouTube.
  3. Run the security checklist on every camera.

Questions people ask

Is port forwarding a security camera safe?

No, it is the riskiest way to view a camera remotely. It lets anyone on the internet reach the camera, and automated scanners look for exactly that. Use the maker’s app with two-step login, a VPN, or push the stream to a platform instead.

What is P2P on a security camera?

It means the camera connects out to the maker’s service, which links your phone and camera without any port forwarding. It is much safer than an open port, but you depend on the maker’s security, so use a strong password and two-step login.

Should I turn off UPnP?

In most homes and small businesses, yes. UPnP lets devices open ports on your router automatically. CISA advised disabling it unless it is essential after the Mirai botnet attacks.

How do I share my camera with the public safely?

Push the stream out to a platform like YouTube over RTMPS and share or embed the platform’s player. Viewers never connect to your camera or network.

How do I know if my camera is exposed to the internet?

Check your router for port forwards, DMZ settings and UPnP mappings. If any point to the camera, remove them, update the firmware and change the passwords.

Sources

  1. CISA: Heightened DDoS threat posed by Mirai and other botnets (checked 2026-10-07)
  2. FTC: TRENDnet settlement over internet-connected cameras (2013) (checked 2026-10-07)
  3. CISA: Securing network infrastructure devices (checked 2026-10-07)
  4. NCSC (UK): The smart devices law (PSTI) (checked 2026-10-07)
  5. RFC 7826: Real-Time Streaming Protocol Version 2.0 (IETF) (checked 2026-10-07)
  6. YouTube Help: Create a live stream with an encoder (checked 2026-10-07)

Last reviewed October 7, 2026 by the LiveLocation team. General information, not legal or electrical advice.