Noob alert: How to "secure" my NAS/Network

Soldato
Joined
18 Oct 2002
Posts
4,757
Location
Kent
I put together my own little Xpenology NAS a few weeks ago and it was my first experience with proper home networking, i'd only ever setup a couple of routers before.

Being completely new to using Synology DSM and configuring both the NAS and connected devices i've had to follow a lot of guides as well as just blindly clicking buttons in order to setup DS Cloud Sync, Plex, Sabnzdb, Sonarr, Kodi etc etc.

My concern is that having made changes to permissions and opening ports in my router and allowing devices outside my network to connect to it (my brother's phone and laptop) I may have inadvertently left the NAS and/or the devices connected to it vulnerable. I thought i'd include a few screenshots of various settings i've changed in the process of trying to configure the NAS, installed packages, devices, router etc in case i've done some something obviously wrong.

Control Panel:

Iakla1b.jpg

Typical Shared Folder Options:

cxmqeGu.jpg

EXwNFad.png

0R3wAcv.png

File Services:

ibJNFg0.png

Control Panel > User:

b4v2Dry.png

Typical User Settings:

o4FeORY.png

PRHZS1i.png

tPlv1BU.png

Control Panel > Group

XmShxdn.png

ar1Pp3z.png

Control Panel > Network:

3JvlJlT

XOF9OQa.png

P1cavu5.png

Control Panel > Info Center

21KQcv6.png

Control Panel > Web Services

MdIfKE9.png

Router Port Forwarding (this was for Sab and Sonarr i believe)

dUV0WYj.png


Ok so that turned out to be a lot more screenshots than I thought i'd do, hopefully someone might given them a quick glance :)

Any other general advice would be most appreciated.

Thanks
 
Last edited:
i see you opened 5000 as a http service, and also enabled https but didnt do the port forward for it, i would change 5000 to 5001 and change the protocol from all to tcp
 
Removing the port forwarding rule should be enough.

Do you need local web access to the unit?
 
Removing the port forwarding rule should be enough.

Do you need local web access to the unit?

All i was looking to do was setup DS Cloud/Sync to run on my brother's iPhone and laptop in order to sync a folder for photo's and whatnot. I'd like to allow him access to my Plex server too but that's of secondary importance.
 
Yeah I wouldn't open the web admin login myself if I could avoid it, I have port forwarded a few things but not the ability to logon to my NAS and change anything that way.
 
Back
Top Bottom