Thanks for the reply, but I really need someone to be very specific. You are saying port forward from the external WAN to the LAN interface of the CCTV, ok fine, but what should be allowed out from the internal LAN to the external WAN?
AFAIK "Home" firewalls tend to block incoming connections, but often allow all traffic outbound, but business firewalls by default block traffic both ways, so rules have to be set to allow traffic to flow from the LAN to the WAN interface.
So you are suggesting port forwarding from external WAN to the LAN interface of the CCTV PC, but what should be 'allowed' to flow from the internal LAN to the external WAN interface?