Remote Viewing Factory CCTV Behind Jio/Airtel CGNAT: How to Tell and What Works
If the WAN IP shown on your Jio or Airtel router starts with 100.64 to 100.127 (the 100.64.0.0/10 block reserved by RFC 6598 for carrier-grade NAT), you are behind CGNAT and no port-forward on your router will reach the NVR. Fix it with a business-plan public static IP, the vendor's P2P cloud, or a VPN overlay.
Verified against
- IETF RFC 6598 / BCP 153, "IANA-Reserved IPv4 Prefix for Shared Address Space", April 2012.
- IETF RFC 1918, private address ranges.
- Jio: Business Broadband Max (plan notes and FAQ) and Business Internet Line (FAQ) product pages.
- Airtel: Office Internet / Campus Wi-Fi FAQ (undated), Static IP for Education blog (dated 11 Aug 2026), Corporate plans guide blog (dated 20 Apr 2026).
- Hikvision: network camera user manual, Enable Hik-Connect Service via Web Browser; Hikvision USA support, Troubleshooting platform access offline.
- Dahua: Dahua Wiki — NVR P2P Troubleshoot (page last modified 16 Mar 2016; newer NVR menus may differ).
- Tailscale: 100.x addresses, DERP servers, Subnet routers.
- CISA Known Exploited Vulnerabilities catalog (JSON feed).
- Checked 7 Oct 2026.
- Not verified: a static IP add-on on Jio or Airtel home plans (no consumer page states one); inbound IPv6 on residential plans; CP Plus and Dahua P2P server ports (no primary document found); which Airtel Office Internet plans include a static IP (Airtel's pages disagree, see below).
How to tell if you are behind CGNAT
| Check | What you see | What it means | Source |
|---|---|---|---|
| Router status page → WAN/Internet IPv4 | 100.64.0.0 – 100.127.255.255 | Shared Address Space for CGN; you share a public IP with other subscribers | RFC 6598 |
| Router WAN IPv4 | 10.x.x.x, 172.16–31.x.x or 192.168.x.x | Private address; there is another NAT upstream | RFC 1918 §3 |
| Router WAN IPv4 vs. any "what is my IP" site | Different numbers | Upstream NAT; port forwards on your router never see outside traffic | RFC 6598 (CGN model) |
| Router WAN IPv4 = "what is my IP" | Same public number | No CGNAT; port forwarding can work (but read the security section) | — |
One trap: Tailscale also hands out addresses from 100.64.0.0/10 (Tailscale KB 1015). A 100.x address on a laptop's Tailscale adapter is not your ISP's CGNAT; read the router's WAN IP.
Remote-access options, compared
| Option | Works behind CGNAT? | What the source says | Main trade-off | Source |
|---|---|---|---|---|
| Port forwarding on the home/office router | No | RFC 6598 §4: Shared Address Space packets "MUST NOT be forwarded across Service Provider boundaries" | Even with a public IP, exposes the NVR web/SDK port to the internet | RFC 6598 |
| Jio business public static IP | Yes (bypasses CGNAT) | Business Broadband Max (sold by Jio as an AirFiber service): "Public Static IP is provided directly to the customer's device", one static IP per plan, only on LAN port 2 of the Business Gateway; on 1 Gbps plans that port runs "up to 200 Mbps". Business Internet Line FAQ: "provides static IP for your business" | Business plan required; other LAN ports and Wi-Fi get a private dynamic IP per Jio; 200 Mbps cap on the static-IP port | Jio BB Max, Jio BIL |
| Airtel Office Internet static IP | Yes | FAQ (undated): "Airtel offers free static IP to ensure a stable network for… accessing devices remotely" and "Most Airtel Office Internet plans are bundled with… free static IP". Education blog (11 Aug 2026): the ₹1,499 office plan "includes 300 Mbps… and one free static IP", and "All Airtel office internet plans come with… static IP included as standard". Corporate guide (20 Apr 2026): Office Internet "starts around ₹999/month at 200 Mbps, with free static IP on 300 Mbps+ tiers". These disagree | Confirm in writing whether your plan includes a public static IPv4 | Airtel FAQ, Airtel edu blog, Airtel corporate guide |
| Hikvision Hik-Connect (P2P cloud) | Yes (device dials out) | Camera web UI: Configuration > Network > Advanced Settings > Platform Access, select Hik-Connect, Enable, set verification code; Hikvision USA support: check that "the STUN ports are not closed by the firewall: 6002, 6800, 8555, 9010, and 9020" | Device registration and the user account sit with the vendor's cloud | Hikvision doc, Hikvision USA support |
| Dahua P2P | Yes (device dials out) | NVR: Main Menu > Setup > Network > P2P (the same page also writes Main menu > Setting > Network > P2P), enable, status must read "Online"; enable DHCP and reboot if not | Same vendor-cloud dependence; no ports listed in that doc | Dahua Wiki |
| VPN/overlay (e.g. Tailscale) with a subnet router on site | Yes | When a direct connection isn't possible it tries peer relays, then falls back to DERP relay servers; relayed traffic is WireGuard-encrypted and "impossible for a DERP server to decrypt"; subnet routers bring in "devices that can't run the Tailscale client" — i.e. the NVR | Needs a small always-on box at the plant; routes must be approved in the admin console | DERP, Subnets |
Where brands differ
- Hikvision documents the outbound ports for its P2P service and, when Platform Access stays offline, suggests switching the server to dev.hik-connect.com or litedev.hik-connect.com and DNS to 8.8.8.8 (Hikvision USA support). Prama (Hikvision-based) units in India: check whether the menu reads Hik-Connect or a Prama-branded service — not confirmed from a Prama document.
- Dahua uses a P2P serial-number/QR model; the Dahua Wiki troubleshooting page gives menu path and "Online" status but no port list. Users report that CP Plus recorders show the same "Cloud/P2P" menu and pair with the gCMOB app — not confirmed from a CP Plus primary document.
- For RTSP/ONVIF strings once you are inside the network (VPN option), see the RTSP and ONVIF cheat sheet for Indian brands and the CP Plus RTSP URL page.
Why port forwarding is a risk even when it works
CISA lists these camera/NVR flaws as actively exploited (KEV catalog):
| CVE | Vendor | Issue (CISA wording, shortened) | Added to KEV |
|---|---|---|---|
| CVE-2021-36260 | Hikvision | Command injection in the web server | 10 Jan 2022 |
| CVE-2021-33044 | Dahua | Authentication bypass (NetKeyboard type) | 21 Aug 2024 |
| CVE-2021-33045 | Dahua | Authentication bypass (loopback device) | 21 Aug 2024 |
| CVE-2017-7921 | Hikvision | Improper authentication, privilege escalation | 5 Mar 2026 |
An NVR web port forwarded to the internet on old firmware is exactly what these exploits target. If you do forward a port on a public static IP, treat it as a last resort: current firmware, no default or shared passwords, only the ports you need, and a firewall allow-list of known source IPs. The P2P and VPN routes keep inbound ports closed, which is why they are the safer default. Our unsecured camera feeds audit checklist covers the rest.
What breaks in a factory
- Two links, two NATs. Plants often run a Jio or Airtel fibre plus a backup (4G/5G router or a second fibre). Failover can silently move the NVR to a CGNAT link: P2P keeps working, a port-forward bookmark dies.
- Camera VLAN without internet. If cameras sit on an isolated VLAN or a separate switch with no route out, P2P shows "Offline" exactly as Dahua's checklist describes — the cloud is not the problem, the gateway is. A VPN subnet router placed on the camera VLAN avoids opening that VLAN to the internet.
- Power cuts. After a mains drop the ONT, router and NVR boot in different orders; P2P re-registers on its own, a VPN box needs to auto-start. Put the ONT, router and VPN box on the same UPS as the NVR.
- Upload bandwidth. Remote main-stream viewing of several 4 MP cameras eats upload; use sub-streams for phones (see cloud vs edge AI on Indian links).
When to call the installer / what to ask the ISP
Ask the ISP, in writing: (1) Is my WAN IPv4 behind CGNAT? (2) Which business plan gives a public static IPv4, at what monthly charge, and on which router port? (3) Is any port blocked inbound? Ask the installer: NVR and camera firmware versions against the CVEs above, and which P2P account owns the devices (the company's, not the installer's).
Where Mama fits
Mama reads a factory's existing cameras over RTSP/ONVIF to report machine idle time to the owner; outbound-only paths like the VPN option above avoid opening NVR ports. To discuss your site, leave an email or phone in the form below.
FAQ
Does Jio Fiber use CGNAT? Users report that home JioFiber connections sit behind CGNAT and router port forwarding does not open ports to the outside (techenclave thread). Jio's own business pages state a public static IP on Business Broadband Max and Business Internet Line; we found no Jio consumer page stating one. Check your router's WAN IP against 100.64.0.0/10 to be sure.
Can I view my CCTV remotely without a static IP? Yes. Vendor P2P (Hik-Connect, Dahua P2P) and VPN overlays both connect outbound from the site, so they work behind CGNAT. A static IP is only needed for direct inbound access.
Why does port forwarding on my Airtel router not work? If the router's WAN IP is in 100.64.0.0/10 or another private range, the forward is behind a second NAT you do not control. Users report Airtel support asking for a static IP to enable inbound access (techenclave); Airtel's Office Internet FAQ lists static IP for "accessing devices remotely".
Is Hik-Connect safer than port forwarding? It keeps inbound ports closed, which removes direct exposure to web-server exploits like CVE-2021-36260, but it puts the device behind a vendor cloud account. Keep firmware current either way, and keep where your footage is stored in your own hands.