How to Set up Firewall on Synology NAS (and why you probably do not need one)

Ғылым және технология

This tutorial goes over how to set up a firewall on a Synology NAS. A firewall allows you to only accept traffic from specific IP addresses or subnets on specific ports. Most Synology users likely do not require a firewall due to the fact that their router will act as the firewall.
#synology #firewall #networking
Hire Me! www.spacerex.co/hire-me/?utm_...
Support the Channel & Get Early Access to ALL Videos: / spacerexwill
Post on the forums: forums.spacerex.co
More DSM 7.2 Videos:
DSM 7.2 release video: • DSM 7.2 Finally Releas...
SMB Multichannel: • DOUBLE YOUR Performanc...
Overview of DSM 7.2: • Synology DSM 7.2 Beta ...
Container Manager (previously docker): • DSM 7.2 Beta - Contain...
Best Synology Line up*:
DS923+ : amzn.to/3IFQb79
DS1621+: amzn.to/3SesIge
DS1821+: amzn.to/3IhBaXr
RS1221+: amzn.to/3SiOL5I
Desk accessories (desk pad, keyboard stand, wrist rest)*: bit.ly/3qRKix8 , discount code SPACEREX for 10% off
TOC
00:00 Introduction
01:09 What is a firewall?
02:17 Overview of firewalls on Synology
05:03 Setting up the firewall
06:54 Basic firewall rules (local network access only)
13:08 Configuring to allow remote access
17:18 A few closing notes
*These are affiliate links, which means that if you purchase a product through one of them, I will receive a small commission (at no additional cost to you). Thank you for supporting my channel!

Пікірлер: 58

  • @billyjoe3309
    @billyjoe3309Ай бұрын

    SpaceRex is the hero of Synology. They really should pay this guy. He's bringing lots of value!

  • @xpyres2130
    @xpyres2130 Жыл бұрын

    Your channel is one of my go-to places when I need help or info on my NAS.

  • @SpaceRexWill

    @SpaceRexWill

    Жыл бұрын

    Thanks man!

  • @cyberwasp461
    @cyberwasp461 Жыл бұрын

    Fantastic Tutorial Will. I still don't fully understand the numbers, but I used the ones you provided and tested it with my phone. Works great. A lot less complicated than my old one.

  • @johnhersom6002
    @johnhersom6002Ай бұрын

    I greatly appreciate all of your Synology videos. You speak so clearly and calmly...you have helped me so much during my first Synology configuration. Thank you!!

  • @versa319
    @versa319 Жыл бұрын

    Great tutorial, Will! Excellent information. Thanks again buddy! 😊

  • @umbertoelia3029
    @umbertoelia3029 Жыл бұрын

    Bellissimo video! Finalmente ho risolto il mio problema di attaccchi al mio NAS da varie parti del mondo. Fino a qualche settimana fa avevo messaggi continui da parte del mio NAS di accessi non desiderati con i relativi indirizzi IP, dopo aver impostato il firewall, seguendo il tuo video, i messaggi sono completamente spariti!!! FINALMENTE!!! Seguo sempre i tuoi video molto semplici e professionali, continua così perché sei unico! Non voglio tradurre il testo con google perché voglio che si capisca che ti seguo dall'Italia... Grazie

  • @carstenskjoed9026
    @carstenskjoed9026 Жыл бұрын

    It's really what I was looking for, thanks SpaceRex.🙏

  • @thomascanty4649
    @thomascanty4649 Жыл бұрын

    This is exactly what I was looking for. Thanks, Will!

  • @SaschiIein
    @SaschiIein Жыл бұрын

    Very useful, thank you for uploading! Now I have to reconfigure my NASes ;-) Greetings from Germany!

  • @ygiagam
    @ygiagam Жыл бұрын

    Thanks, Will. This is very useful information and you explained it well.

  • @Adamation2011
    @Adamation2011 Жыл бұрын

    Could not have come at a better time, Thankyou.

  • @peerview
    @peerview Жыл бұрын

    As you mention during the video, another video talking about network and subnet and would be great

  • @ms7165
    @ms7165 Жыл бұрын

    Timely and simple. Thanks

  • @Crushertalos
    @Crushertalos7 ай бұрын

    Really great video! Your channel has always been very helpful and I want to thank you for all of your hard work. Keep it up!

  • @tato2700
    @tato27009 ай бұрын

    Great guide, helped me a lot. thanks!

  • @mingfx
    @mingfx10 ай бұрын

    great tutorial, very helpful, Thanks a lot

  • @superbaggio87
    @superbaggio87 Жыл бұрын

    very very VERY usefull and well explained. Thanks and salute from italy

  • @pjgodier
    @pjgodier Жыл бұрын

    Thanks!

  • @matteominellono
    @matteominellono Жыл бұрын

    Will I discovered that with DSM 7.2 if you lock yourself out, it goes back to a previous firewall configuration to avoid it, and a pop-up window will even warn you about it!

  • @SpaceRexWill

    @SpaceRexWill

    Жыл бұрын

    Thats quite useful!

  • @ibclay1433
    @ibclay1433Ай бұрын

    "Hey", very good video. Tks.

  • @SaschiIein
    @SaschiIein Жыл бұрын

    How would you organize the following: clients (win/linux) backup data onto a smb share on a synology NAS. Now the data is backuped but not save against viruses that encrypt data because the share is available (I found no was to set security setting, that the clients can write data but not change or delete it). So I would backup this NAS-backup share with e.g. HyperBackup to another NAS - now this backup is absolutely safe. You see another, perhaps easier way?

  • @tonyvalenti6614
    @tonyvalenti6614 Жыл бұрын

    Great video Will! Thanks for showing us how to setup firewall security in an understandable way. One question, when using a Tailscale VPN, it assigns different IP addresses to each device that are not part of the three private networks you discussed. Should we add the Tailscale IP to the firewall and allow it? I have yet to setup my Synology firewall yet with All Denied yet so want to be sure that if I did, my Tailscale network would still work. Thanks again! 👍🏻👍🏻

  • @SpaceRexWill

    @SpaceRexWill

    Жыл бұрын

    Ah, so with TailScale I think the traffic actually comes in via the local app (does not act like a normal VPN) so you may not have to do anything. But if it does get blocked you can open up the CGNAT subnet the same way you did the other 3. Just with the following info: IP: 100.64.0.0 Subnet mask: 255.192.0.0

  • @tonyvalenti6614

    @tonyvalenti6614

    Жыл бұрын

    @@SpaceRexWill Great! Thank you! Since my Tailscale hands out IP’s with different second octets, would it be? … IP: 100.0.0.0 Subnet Mask: 255.0.0.0

  • @simranbajwa9299
    @simranbajwa9299 Жыл бұрын

    Is your Time machine backup video from 3 years ago still valid since a lot has changed with new DSM versions? If so, maybe a new video on this topic?

  • @pedrohermida7080
    @pedrohermida7080Ай бұрын

    Again, great video. While creating rules, you must select the interface(s) to apply them to. If I want to block DSM from ALL over the world except the US, I will use your example and applied to my BONDed interface. Now, I as travel, I want to be able to access DSM from ALL over the world as long as I connect to DSM's VPN Server. I guess I will have then one restrictive rule under BOND 1 and one permissive one (or at least no one blocking) for DSM over the VPN interface. Is that correct?

  • @angelldark6426
    @angelldark6426Ай бұрын

    Hello, Do you have a video where you show how to configure (CAPTCHA) for entering Synology nas??

  • @VerticalBlank
    @VerticalBlank Жыл бұрын

    Thank you! What about IPv6? Just had a look on my own NAS and it only seems to have options for IPv4.

  • @SpaceRexWill

    @SpaceRexWill

    Жыл бұрын

    I have not dealt with IPv6 too much, so I can’t be too much help!

  • @alexlora6009
    @alexlora60099 ай бұрын

    the Synology has a console for watch the firewall logs?

  • @silvahawk
    @silvahawk8 ай бұрын

    If i want to allow access to Plex remotely, should i set allow "custom" port in the firewall to 32400?

  • @envirophile
    @envirophile2 ай бұрын

    i get an error "failed to load profile data" and can't add any rules. any idea how to correct it?

  • @matteoc7084
    @matteoc70846 ай бұрын

    How does firewall work with reverse proxy? I want to allow access to certain docker apps like Jellyfin when accessing from reverse proxy. But adding port 8096 as a rule wont work, instead its port 443. However then it allow access to all my other docker apps. Is there a way to limit firewall access to only one docker app with reverse proxy?

  • @geoffreyleavitt6835
    @geoffreyleavitt68356 ай бұрын

    I have a Synology router as well as a Synology NAS, would you say that the same firewall rules can be used for the router?

  • @marcussaastamoinen6359
    @marcussaastamoinen63598 ай бұрын

    The synology Firewall does not work. I block ALL IPS but my LAN and My friend can still access my nas??? Please explain

  • @DavidM2002
    @DavidM2002 Жыл бұрын

    Very timely Will; many thanks. I was just going through my Synology router and DS920+ last night and considering exactly this. On the NAS, there is a section : Control Panel \ Security \ Protection \ Allow/Block List that presumably provides at least some additional protection without setting up the firewall ?

  • @davewhite7182

    @davewhite7182

    Жыл бұрын

    It allows you to block traffic from a specific ip address. I have a limit on the number of login attempts and then a block is set up. I have had occasions of someone with a Russian ip address trying to access my NAS and so added them to the block list on my other NAS. I once blocked myself as I was using the wrong password and had to go in from another device and remove myself from the list!

  • @SpaceRexWill

    @SpaceRexWill

    Жыл бұрын

    Yes! I will always add autoblock to any network and any NAS. This prevents people just brute force password guessing. Even if you set it to 100 every 10 min you will keep machines from brute forcing. Autoblock can be used in tandem with Firewall

  • @DavidM2002

    @DavidM2002

    Жыл бұрын

    @@SpaceRexWill The Allow/Block list is just below Auto block. They are very different settings.

  • @DavidM2002

    @DavidM2002

    Жыл бұрын

    @@davewhite7182 The Allow/Block list is just below Auto block. They are very different settings.

  • @SpaceRexWill

    @SpaceRexWill

    Жыл бұрын

    Ah when a device is auto blocked it’s put in the block list. But if something is in the allow list it will never get blocked

  • @bobmoore1954
    @bobmoore1954 Жыл бұрын

    Would it make sense to apply the same LAN IP configuration on your router?

  • @SpaceRexWill

    @SpaceRexWill

    Жыл бұрын

    Your router likely is already doing this

  • @MC-ExcaliburProject
    @MC-ExcaliburProject6 ай бұрын

    What is a docker?

  • @51Fathermo
    @51FathermoАй бұрын

    Hi, I am trying to backup files to my Synology NAS from my computer using Acronis. If I leave fire wall off it works if I turn firewall on it doesn't. Any idea of the rules I need. Thank you.

  • @51Fathermo

    @51Fathermo

    Ай бұрын

    Ah found it ty.

  • @derekaxtell5397
    @derekaxtell53979 ай бұрын

    Great tutorial but my Firewall is now greyed out and i cannot access at all. Please help with firewall problems.

  • @supertekkel1
    @supertekkel1 Жыл бұрын

    This helped me. I got someone (a bot) who kept trying to login onto the disabled admin account every 2 minutes. It was really annoying. After setting the firewall (and changing the standard dsm ports) it finally stopped. B.T.W. autoblock didn't work, the bot was using different ip's every time.

  • @alanstei5680

    @alanstei5680

    Жыл бұрын

    I have the same issue, how did you make that change?

  • @supertekkel1

    @supertekkel1

    Жыл бұрын

    @@alanstei5680 search for DSM Port in Settings. Mind you that you wil have to change portforwarding on your router too if you have that set up.

  • @Snobbias
    @Snobbias Жыл бұрын

    Synology is actually warning you if you're about to lock yourself out using the firewall so I don't even think it's possible. I have a request: Could you please make a guide on how to enable the firewall log in iptables and then how to send that log to a syslog server? I'm struggling with my poor Linux knowledge.

  • @PatrickBijvoet
    @PatrickBijvoet Жыл бұрын

    My conclusion, as there is a good firewall in my router, I will stick to your first advice and not set this up. Thanks again.

  • @EmilePolka
    @EmilePolka Жыл бұрын

    the last rule doesnt many anything unless you directly expose that NAS to a public ip address. the reason is NAT, your NAS will always see any traffic from outside coming from your main router's ip address. so the proper way to block connections from internet is basically add your router's IP address as your block rule if your aim is block any connection attempt on your NAS that is coming outside your local network,

  • @SpaceRexWill

    @SpaceRexWill

    Жыл бұрын

    This is not true. The process you are talking about where the traffic looks like it is coming from the router is NAT Masquerading. This is a very rare and niche feature that 99.9% of routers do not support. Port forwarding will show the public IP of the computer connecting to the NAS. You can try for yourself. Open up 5001 to the NAS and connect from your phone off WiFi. You will see your phones public in the connection logs

Келесі