How do you set a secure password and remote access on an IP camera?

Get a new IP camera safely viewable from anywhere in 60-90 minutes, with no forwarded ports and no factory password left in place.

Duvara monte beyaz IP kamera ve altındaki masada açık dizüstü bilgisayar, Ethernet kablosu ile tornavida

Short answer

On first boot, connect the camera to your router with Ethernet and use the vendor tool (Hikvision SADP, Dahua ConfigTool, or the Tapo/EZVIZ app) to set your own password of 14 characters or more. For remote viewing, skip port forwarding: use the vendor P2P cloud service (Hik-Connect, DMSS, Tapo) with two-step verification, or run a VPN on your router. Then disable UPnP and update the firmware.

What you need

IP camera (PoE or Wi-Fi) with its original 12V adapter
Cat6 Ethernet cable, 10-30 m depending on the run to the router
PoE switch or PoE injector (for PoE cameras)
Windows or macOS computer to run SADP or ConfigTool
Smartphone with the vendor app (Hik-Connect, DMSS, Tapo, EZVIZ)
Password manager such as Bitwarden or KeePassXC
Router admin username and password (usually printed on the label)

Step by step

01

Connect the camera to the local network

Run a Cat6 cable from the camera to the router or PoE switch and power it up. Do the first setup over cable even on Wi-Fi models, because some of them pass the setup password over an unencrypted link. The camera needs 30-60 seconds until its LED stops blinking.

02

Set the admin password yourself

Open SADP for Hikvision or ConfigTool for Dahua. The camera appears in the list with the status Inactive. On the Activate screen, give admin a new 14-20 character password mixing upper and lower case, digits and symbols. Save it in your password manager, not on a note next to the camera.

03

Log in to the web interface and add a second account

Type the camera IP (for example 192.168.1.64) in a browser and sign in as admin. Go to Configuration > System > User Management > Add and create a separate account with Operator rights for day-to-day viewing. If a phone goes missing, you only delete that one account instead of rotating the admin password.

04

Turn off UPnP and port forwarding

In Configuration > Network > Advanced Settings > UPnP, clear the Enable UPnP checkbox and press Save. In your router, open Port Forwarding or NAT and delete any camera rules for ports such as 80, 554 and 8000. Camera ports exposed to the internet are the first thing automated scanners look for.

05

Set up remote access through the P2P cloud

In Configuration > Network > Advanced Settings > Platform Access, tick Enable, type your own 8-12 character code in the Verification Code field and press Save. In Hik-Connect or DMSS on your phone, add the camera by scanning its serial number QR code. Then turn on Account > Two-Step Verification for the app account.

06

Enable HTTPS and change the ports

In Configuration > Network > Advanced Settings > HTTPS, tick Enable HTTPS and use Create self-signed certificate to generate one. On the Port tab, move the HTTP port from 80 to something like 8080. Opening the interface over https keeps your password from crossing even the local network in clear text.

07

Update the firmware

Download the .dav or .bin file that matches your exact model from the vendor's official support site. Go to Configuration > System > Maintenance > Upgrade, pick the file and press Upgrade. It takes 3-5 minutes, and cutting power during the flash can brick the camera. Old firmware often carries known password bypass flaws.

08

Review the logs and lock out attackers

About a week after setup, open Configuration > System > Log and filter Minor Type by Illegal Login. If you see repeated attempts from IP addresses you do not recognise, change the password and enable Security > Illegal Login Lock so the account locks after five failed tries.

Ad — in-article responsive

Tips

Keep names, surnames, plate numbers, birth years and patterns like admin123 out of the password; three random words plus a digit and a symbol is both strong and memorable.
If your router supports it, put the camera on the guest network or a separate VLAN so a compromised camera cannot reach your computer or NAS.
Give the camera a static address instead of DHCP under Configuration > Network > TCP/IP > Static, so the app connection does not break when the lease changes.
If you are comfortable with networking, a tighter option than the P2P cloud is running WireGuard or OpenVPN on your router and viewing only over the VPN.
Use a dedicated email address for the cloud account and enable two-step verification on that mailbox too.

Watch out

The most common mistake is forwarding port 80 or 8000 to the camera for convenience and leaving the factory password in place. Internet-exposed cameras are scanned automatically within minutes, and your footage can end up on public open-camera listing sites. If you have already forwarded ports, delete the rule and change both the password and the verification code from scratch.

Frequently asked questions

+I forgot the password. How do I reset the camera?

Hold the RESET button on the camera body for 10-20 seconds while it is powered on; it returns to factory defaults and shows as Inactive again. Some models require a GUID or encryption file from the vendor, so set a security question and recovery email during the first setup.

+My ISP uses CGNAT. Can I still watch remotely?

Yes. You cannot forward ports behind CGNAT, but P2P cloud services like Hik-Connect, DMSS and Tapo work fine because the camera opens the connection outbound. You do not need to buy a static IP address.

+Can I keep the footage locally instead of in the cloud?

Yes. Fit a 64-256 GB microSD card and set continuous recording under Configuration > Storage > Schedule Settings, or connect the camera to an NVR. You then only need the cloud for live viewing.

+Is it legal to point a camera at the street or a neighbour's garden?

Recording beyond your own door and garden counts as processing personal data under most privacy laws and can trigger a complaint. Limit the camera angle to your own property and use the Privacy Mask feature to black out neighbouring areas.

+How long does the whole setup take?

Excluding cable runs, setting the password, configuring the cloud, enabling HTTPS and updating firmware takes 60-90 minutes for a single camera. The firmware update alone is 3-5 minutes.

Sources and verification

Last verified: September 15, 2026. tell us. Menu paths follow Hikvision and Dahua English firmware; privacy rules cited are generic, so check your local data protection law (in Turkey, KVKK) for camera coverage limits.

This content is for information only; for official procedures the relevant institution’s current announcements take precedence. Details: disclaimer.

N?
Nasıl Yapabilir? Editör Ekibi

Resmî kaynaklara dayanan, Türkiye için yazılmış adım adım rehberler. Our editorial principles →