远程访问
远程访问的首要目标是安全,而不是简单端口映射。优先使用 VPN/Tailscale、受控反向代理或零信任入口,并使用 HTTPS。
核心说明
本页内容按该功能本身整理,不再使用通用占位说明。以下项目均与当前主题直接相关。
避免裸端口
不要把内部管理端口、go2rtc 管理口或数据库端口直接映射到公网。
证书
移动端和浏览器都更适合使用受信任 HTTPS 证书;自签名证书可能导致登录或媒体请求失败。
带宽
远程实时和回放可能消耗较高上行带宽;必要时使用较低码率 restream。
审计
定期检查登录、代理和系统日志;发现异常访问时及时撤销凭据并更新。
验证与排查
- 修改或执行前记录当前版本/配置,以便回退。
- 完成后同时检查 UI 状态和后端日志,不只看一个成功提示。
- 如果问题只在单个摄像头/插件出现,先做最小范围对比,避免全局改动。
Remote Access
Remote access should prioritize security over simple port forwarding. Prefer VPN/Tailscale, a controlled reverse proxy or zero-trust gateway with HTTPS.
Core behavior
This page is topic-specific rather than a generic placeholder.
Avoid raw exposure
Do not expose internal management, go2rtc admin or database ports publicly.
Certificates
Trusted HTTPS certificates provide the best browser/mobile compatibility.
Bandwidth
Remote live/playback consumes upstream bandwidth; provide a lower-bitrate stream when needed.
Audit
Review login/proxy/system logs and rotate compromised credentials promptly.
Verification and troubleshooting
- Record the current version/config before changes so rollback is possible.
- Verify both UI state and backend logs after the change.
- If only one camera/plugin is affected, isolate it before making global changes.
Acceso remoto
El acceso remoto debe priorizar seguridad. Prefiera VPN/Tailscale, proxy controlado o gateway zero-trust con HTTPS.
Comportamiento
Esta página contiene contenido específico del tema, no un texto genérico.
Evitar exposición
No exponga puertos internos de administración o base de datos.
Certificados
Use certificados HTTPS confiables para navegador y móvil.
Ancho de banda
Live/remoto consume subida; use stream de menor bitrate si hace falta.
Auditoría
Revise logs y cambie credenciales comprometidas.
Verificación y diagnóstico
- Registre versión/configuración antes de cambiar para poder revertir.
- Compruebe UI y logs del backend después.
- Si afecta a una sola cámara/plugin, aíslelo antes de cambios globales.
