Enterprise Data-in-Transit Encryption & Firewall Traversal

Secure Camera Connectivity & WireGuard Tunneling

How FireVision solves complex firewall restrictions, carrier-grade NAT, and dynamic IP challenges using pre-installed WireGuard edge gateways and cryptographic data-in-transit protection.

Featured Deployment Option

Pre-Installed Secure WireGuard Pi Gateway

Order Pre-Configured Hub
Zero Port Forwarding

Establishes an outbound-only UDP tunnel. Leaves 0 inbound ports open on your router, completely eliminating public exposure and botnet attacks.

ChaCha20-Poly1305 Cryptography

Every video frame is encrypted with state-of-the-art Curve25519 ECDH key exchanges and authenticated ciphers for maximum data-in-transit privacy.

Bypasses Strict Firewalls & CGNAT

Seamlessly tunnels through Carrier-Grade NAT, double routers, 4G/5G mobile broadband, and restricted enterprise VLANs without IP conflicts.

How the Pre-Installed Gateway Works Out-of-the-Box

When you order a pre-installed gateway, our engineers assign a dedicated cryptographic key-pair and WireGuard tunnel IP (piWireguardIp) linked to your account. You simply connect the Raspberry Pi to your local network switch. It automatically establishes the encrypted tunnel with our UK Manchester AI cluster, bridges to your local camera IP addresses, and begins real-time stream analysis—with 0 software installation required on your PCs.

Connection Methods & Security Comparison

Why WireGuard edge appliances offer the highest security and simplest deployment for commercial CCTV systems.

Feature / MetricPre-Installed Pi GatewayManual DIY PiVPNTraditional Port Forwarding
Setup Time< 2 Minutes (Plug & Play)30–45 Minutes15–30 Minutes
Firewall Inbound Ports0 Ports Open (Outbound Only)1 Port Open (UDP 51820)Multiple Ports Exposed (RTSP/HTTP)
Data-in-Transit EncryptionChaCha20-Poly1305 (WireGuard)ChaCha20-Poly1305 (WireGuard)Often Plaintext RTSP / Digest
CGNAT & 4G SupportFull Support (Persistent Keepalive)Requires Public Dynamic IPFails on CGNAT / 4G / Strict NAT
Local Storage Footprint0 MB (Stateless UK GDPR Bridge)0 MB0 MB
Automated Security UpdatesManaged Unattended UpgradesUser MaintainedDependent on Camera Firmware

Manual DIY Raspberry Pi Setup Guide

For network engineers and advanced users who prefer flashing and managing their own Raspberry Pi 4 appliance.

Prerequisites for Self-Hosted PiVPN

  • Raspberry Pi 4 / 5: Model B with 2GB+ RAM.
  • MicroSD Card: 16GB or larger (Class 10 / A1 recommended).
  • Power Supply: Official Raspberry Pi USB-C power supply (5.1V 3A).
  • Ethernet Cable: For initial configuration and reliable local camera LAN access.
  • A No-IP Account: Free account at www.noip.com for dynamic DNS.
  • Raspberry Pi Imager: To flash the OS onto your MicroSD card.

1Prepare Your Raspberry Pi

First, install the operating system and enable SSH for remote access.

✅ 1.1 Install Raspberry Pi OS with Desktop:

  • Download and run the Raspberry Pi Imager.
  • Choose your Raspberry Pi device, and for the Operating System, select Raspberry Pi OS (other) then Raspberry Pi OS (Legacy, 64-bit) with desktop.
  • Use Raspberry Pi Imager to write the OS to your MicroSD card.
Raspberry Pi Imager selecting the Desktop OS

✅ 1.2 Boot and Connect:

  • Insert the MicroSD card into your Raspberry Pi.
  • Connect the Pi to your router or camera switch via an Ethernet cable.
  • Power on the Raspberry Pi and complete the initial desktop setup.
Zero-Configuration Solution

Skip the Manual Setup: Pre-Installed WireGuard Pi Appliance

Get an enterprise-hardened Raspberry Pi pre-flashed with FireVision WireGuard. Simply connect power and Ethernet to bypass firewalls and establish encrypted camera tunneling in under 2 minutes.

🔗 Need engineering assistance? Contact our UK technical team.

2Install PiVPN with WireGuard

PiVPN is an open-source script that makes setting up a WireGuard VPN server simple and lightweight.

✅ 2.1 Open a Terminal and Run the Installer:

  • On your Raspberry Pi desktop, open a Terminal window.
  • Copy and paste the following command into the terminal and press Enter:
curl -L https://install.pivpn.io | bash
PiVPN installation command in terminal

✅ 2.2 Follow the On-Screen Wizard:

The installer will guide you through a series of questions. Use the arrow keys and Enter to make selections.

  • When asked, select WireGuard as the protocol.
  • Accept the default port (51820) unless your firewall requires a custom UDP port.
  • For the DNS Provider, select your preferred one (e.g., Cloudflare 1.1.1.1 or Google 8.8.8.8).
  • When asked about a Public IP or DNS, select DNS Entry and enter the No-IP hostname you created earlier (e.g., myfirevision.ddns.net).
  • Complete the installation and agree to reboot when prompted.
PiVPN DNS selection screen
Zero-Configuration Solution

Skip the Manual Setup: Pre-Installed WireGuard Pi Appliance

Get an enterprise-hardened Raspberry Pi pre-flashed with FireVision WireGuard. Simply connect power and Ethernet to bypass firewalls and establish encrypted camera tunneling in under 2 minutes.

🔗 Need engineering assistance? Contact our UK technical team.

3Install No-IP Dynamic Update Client (DUC)

Most residential and commercial broadband lines use dynamic IP addresses. The No-IP client automatically updates your hostname when your IP changes.

✅ 3.1 Download and Install:

  • After the Pi reboots, open a Terminal again.
  • Run the following commands one by one:
cd /usr/local/src/ sudo wget http://www.noip.com/client/linux/noip-duc-linux.tar.gz sudo tar xf noip-duc-linux.tar.gz cd noip-2.1.9-1/ sudo make install

During the installation, you will be prompted to enter your No-IP username and password.

No-IP DUC installation in terminal
Zero-Configuration Solution

Skip the Manual Setup: Pre-Installed WireGuard Pi Appliance

Get an enterprise-hardened Raspberry Pi pre-flashed with FireVision WireGuard. Simply connect power and Ethernet to bypass firewalls and establish encrypted camera tunneling in under 2 minutes.

🔗 Need engineering assistance? Contact our UK technical team.

4Generate WireGuard Client Profile

Generate an encrypted peer profile for the FireVision cloud system to connect to your local camera network.

✅ 4.1 Add a New Client:

  • In a Terminal on your Pi, run: pivpn add
  • Enter a name for the client, for example: firevision-server
  • The command will create a .conf file in the /home/pi/configs/ directory.
Adding a new PiVPN client

✅ 4.2 Send the Configuration to Support:

This file contains the cryptographic public keys and endpoints for our UK AI servers to establish the WireGuard handshake.

  • Navigate to the configs folder using the File Manager on your Pi.
  • Attach the firevision-server.conf file and send it to our support team.
  • Do not share this configuration file publicly.
Location of the .conf file
Zero-Configuration Solution

Skip the Manual Setup: Pre-Installed WireGuard Pi Appliance

Get an enterprise-hardened Raspberry Pi pre-flashed with FireVision WireGuard. Simply connect power and Ethernet to bypass firewalls and establish encrypted camera tunneling in under 2 minutes.

🔗 Need engineering assistance? Contact our UK technical team.

5Router Port Forwarding & Camera Linking

Once your VPN server is running, forward the single WireGuard UDP port and link your camera's local IP.

✅ 5.1 Router Port Forwarding:

  • Log in to your internet router or firewall admin interface.
  • Locate the Port Forwarding or NAT Rules section.
  • Create a rule forwarding UDP port 51820 to the static local IP address of your Raspberry Pi.
Router port forwarding settings

✅ 5.2 Update Camera Stream URL:

  • Go to your FireVision profile page.
  • Update your camera's RTSP URL to use its local private IP address (e.g., rtsp://admin:pass@192.168.1.50:554/stream1).
  • Since our AI server is now securely peered inside your local network via WireGuard, it accesses the stream directly with zero internet exposure.
Zero-Configuration Solution

Skip the Manual Setup: Pre-Installed WireGuard Pi Appliance

Get an enterprise-hardened Raspberry Pi pre-flashed with FireVision WireGuard. Simply connect power and Ethernet to bypass firewalls and establish encrypted camera tunneling in under 2 minutes.

🔗 Need engineering assistance? Contact our UK technical team.

Manual Setup Verification Checklist

Raspberry Pi OS 64-bit installed
PiVPN WireGuard active on port 51820 UDP
No-IP DUC client running & verified
Client .conf file generated & sent
Router port 51820 UDP forwarded to Pi IP
Local RTSP IP configured in FireVision profile