Synology Firewall - Is this setup correctly?

Soldato
Joined
12 Sep 2003
Posts
11,205
Location
Newcastle, UK
Hello

I've been messing around enabling remote access to my NAS unit, in order to access the Audio Station on my phone. When at home on the Wireless Network, I can login fine from my phone.

So I've setup the HTTPS access and forwarded the correct port, checked via "canyouseeme.org" that the port is visible, then entered my public IP address into my browser and I'm presented with my NAS login screen. YEY!

However, I'm now paranoid about baddies getting in. lol. So, I've enabled IP Block on the NAS, anymore than 3 wrong login attempts and you are blocked. I've also taken a look at the firewall, but now I'm confused! :p

This is what I have in at the minute:-

38ddd0ff.jpg


So basically the 8 LAN devices are things like PC's, Laptops, so I've given them access to everything on the NAS. They're fine.

The last rule is so that I can access the NAS from an external address. Without this rule in, I can't connect via my public IP.

Then finally, set the radio button so everything else is blocked if there is no rule present.

Does this look OK? My only concern is that the last rule says "source IP = ALL". Should I limit this to my external IP? If it is set to "ALL" does that mean any external PC can connect? Basically I only want my phone to connect in remotely. Nothing else.

Is there anything else I can do to improve security?

Thanks!
 
The above is fine. The source IP will need to be set to all for you to access it remotely. Any device will be able to reach it, which is what you want if you're accessing the NAS remotely. So, just make sure your username/password, etc. is complex enough to deter any baddies.

It's a risk you have to take whenever opening anything up to be accessed remotely.
 
For future reference (i know the OP is 4 years old), it'd probably be a bit more secure to enable the VPN Server addon and VPN into the Synology :)
 
For future reference (i know the OP is 4 years old), it'd probably be a bit more secure to enable the VPN Server addon and VPN into the Synology :)

That's assuming your router allows VPN - mine doesn't and my Synology won't connect externally using port forwarding!
 
That's assuming your router allows VPN - mine doesn't and my Synology won't connect externally using port forwarding!

Never had an issue enabling the VPN server on Synology NAS boxes and setting up the correct port forward on the router - yet to come across a router than has prevented me doing that :confused:
 
Back
Top Bottom