Creating Firewall Rules To Secure Your Synology NAS

  Рет қаралды 54,017

Lawrence Systems

Lawrence Systems

Күн бұрын

Пікірлер: 58
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 жыл бұрын
Video I mentioned in regards to Configuring pfsense Firewall Rules For Home kzbin.info/www/bejne/mJvVYaWjbpiojKM More Lawrence Systems Synology Tutorials lawrence.technology/synology/ Getting Stared with pfsense firewall rules kzbin.info/www/bejne/m5OUoYepbL2Uo6M How To Setup VLANS With pfsense & UniFI. Also how to build for firewall rules for VLANS in pfsense kzbin.info/www/bejne/mGPaYoytqZVrZ9E Office Network Design and Planning with VLANs, LLDP, Rules, IoT, Guest using UniFi & pfsense kzbin.info/www/bejne/paakg6VjacibgJo
@webserververse5749
@webserververse5749 2 жыл бұрын
Wait...You use firewalls?
@LinuxRacr
@LinuxRacr 2 жыл бұрын
Awesome that you made this video. Earlier this year I set my firewall rules on my Synology interfaces similar to what you specify for extra security on my network segments. Your guidance has been life-changing to many sir.
@KeithTingle
@KeithTingle 2 жыл бұрын
I enjoy these firewall rules and VLAN videos, I find out how little I really know
@mysticsilent
@mysticsilent 2 жыл бұрын
Great additional security settings i've never thought about. Thanks for this eye opener 😁.
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 жыл бұрын
Happy to help!
@rullywow3834
@rullywow3834 2 жыл бұрын
10.13.37.0 is certainly the leet network lol. Great vid as usual, thanks for making this!
@ronressler
@ronressler 2 жыл бұрын
Perfect timing Tom, I was just days ago pondering the best way to setup my cameras and Synology and you provided a great solution. Thanks and Happy holidays, Ron
@keyboard_g
@keyboard_g 2 жыл бұрын
Nice. Clear and well presented. Thanks, Tom.
@cLickphotographySEA
@cLickphotographySEA 2 жыл бұрын
That was the best explanation of how to firewall rules on the Synology! Thanks
@plrpilot
@plrpilot 2 жыл бұрын
Thanks for this, Tom. Happy New Year!
@mynightoff
@mynightoff 2 жыл бұрын
Excellent - just what I've been waiting for. Many thanks Tom.
@JeppoTheWrecker
@JeppoTheWrecker 2 жыл бұрын
Thanks for doing the video as requested. Very useful.
@MetallicNuance
@MetallicNuance 2 жыл бұрын
Nice summary video. You mentioned the camera network use case, I would love to see an overview of Synology Surveillance Station and a video comparing to UniFi Protect. I'm contemplating the two but thinking since I already have a mid range Synology that Surveillance Station will probably be the better option due to camera costs from Ubiquiti but haven't decided yet and don't yet understand what is needed to get started with S.S. such as licensing. Thanks for the great content!
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 жыл бұрын
kzbin.info/www/bejne/mX_Fkp9mm5ekiqM
@vPeteWalker
@vPeteWalker 2 жыл бұрын
I love this video, Tom. Thank you so much for doing this. I admit I had never considered using multiple interfaces on my Synology for anything other than aggregation (what a dope!) This is a brilliant use, and I hope to implement this soon! I also loved your pfsense video on this, even though I don't use a pfsense router. It gave me a ton of ideas for how to better secure my home network, which I'm always looking for! Thank you once again!
@adam-nw5cn
@adam-nw5cn 2 жыл бұрын
you're a good teacher.
@Arachnoid_of_the_underverse
@Arachnoid_of_the_underverse 2 жыл бұрын
Nice tutorial, thanks Lawrence.
@9juanjuan624
@9juanjuan624 2 жыл бұрын
Great video Lawrence Sys. I use Qnap. I imagine it's similar, given the 2 interfaces. Digging in. Thanks for this!
@Christos9
@Christos9 2 жыл бұрын
If you need to open ports to the internet, you can limit access from a specific country (your country) through the firewall.
@marco.lop88
@marco.lop88 2 жыл бұрын
Hi Tom, thank you for the greate Video ! If you want to add another layer of security. You can moddify the "Admin Group" and allow the "DSM" application only from certian subnets. be carefule to not lock you out ;-)
@Ultrajamz
@Ultrajamz 2 жыл бұрын
So if traffic happens, and the top rule allows it, any rule below it that may deny it, doesn’t count. It goes by the first rule from the top that it ever matches with?
@andylauriewalmsley6102
@andylauriewalmsley6102 2 жыл бұрын
Thanks Tom, Great video - when the trusted network also has access to the Synology on the less trusted network, does that potentially cause asymmetric routing?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 жыл бұрын
You can set the gateway for routing
@anwar.shamim
@anwar.shamim 2 жыл бұрын
Your video makes my day.....thank you
@DJstone17
@DJstone17 9 ай бұрын
So I ask myself, where the difference is in between having a firewall on the system or the firewall on another point in the network, except from network congestion. Maybe you can explain that to me abut further?
@wernerdebijl1885
@wernerdebijl1885 2 жыл бұрын
Great video Tom Tnx.
@christopheoudin3625
@christopheoudin3625 2 жыл бұрын
Hi tanks for this very informative video. Can you do something like that for truenas? Happy new year!
@connorfreebairn6537
@connorfreebairn6537 2 жыл бұрын
Thank you for this.
@fu4616
@fu4616 2 жыл бұрын
Very informative.
@pstgh
@pstgh 11 ай бұрын
I struggle with wanting to be able to look at my cameras remotely, so they need access to the internet, but I don't want China ;-) getting into my LAN which obviously begs for the cameras to have their own interface, but also complicating this scenario is that I have my cameras FTP'ing motion triggered video clips to my NAS. Currently, I have those going to an older NAS which I'm not that concerned about, but I may need to eventually move that backup to my Synology NAS.
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 11 ай бұрын
Use a VPN to remotely access your network
@adrianteri
@adrianteri 2 жыл бұрын
On Synology's part it would be useful to just shortlist the ports/interfaces that are in use when your making the firewall rules.
@burgler2112
@burgler2112 2 жыл бұрын
So I have LAN1 as my secure network for accessing Synology. LAN2 (which is my IOT network) I have blocked as per your video. The issue I'm having though, is now when I'm on my IOT Wifi, I cannot use Photos Mobile backup. I need to switch over to my secure WiFi in order to backup my photos. Any idea on how I can stay on my IOT Wifi and get Photos Mobile through the Synology Firewall?
@---GOD---
@---GOD--- 2 жыл бұрын
If I'm not opening up the NAS to the internet then wouldn't it be easier to manage firewall rules on the router?
@Matushke
@Matushke 2 жыл бұрын
Great video, but this LAN 4 firewall rules only works if you have all cameras on separate PoE switch connected to LAN 4 interface of Synology right?
@jfkastner
@jfkastner 2 жыл бұрын
NOT secure is that the 2nd NAS can be accessed freely by devices from the 192 subnet ... an attacker can place malicious files on the 10 subnet NAS that are then synced back into the 192 subnet (or restored after the 192 NAS fails)
@Axctal
@Axctal 2 жыл бұрын
You can leave first interface for management and then bond 3 other interfaces as LACP, then create any number of VLANs on top of aggregation. Unfortunately Synology GUI only allows you to create one VLAN, extra can be added using SSH ... GUI will show all VLAN interfaces, but all will have same name ...
@TSSC
@TSSC 2 жыл бұрын
I’m curious to if there a specific reason to use the Synology’s firewall compared to your pfsense box? What are the pros and cons? Are there any limitations in any of the methods? I use an EdgeRouter with VLANs, and use the router’s firewall to block/allow access to, for instance, the Synology unit’s management interface. By the way, I have no cameras (which someone in another comment mentioned could burden the router’s firewall; if choosing that option). Thanks for the video, Tom!
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 жыл бұрын
I answered that in the video.
@TSSC
@TSSC 2 жыл бұрын
@@LAWRENCESYSTEMS Thanks. I guess you refer to the note at 10:52. You decide the scope of the video (who else?), so you could take my questions as ideas for future contents. I’m grateful for the content you produce, and wish you a fantastic 2022!
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 жыл бұрын
right in the beginning of the video at 1:22 mark.
@TSSC
@TSSC 2 жыл бұрын
@@LAWRENCESYSTEMS Thanks again for taking the time to respond. It was brief mention that was well placed in the “setting the scene“ introduction, but easily forgotten after having watched the full video.
@daveve6550
@daveve6550 2 жыл бұрын
Thank you, Tom. Great and useful video content, as usual. I was interested which software you used to draw the network design and if there was a free version of it? Cheers!
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 жыл бұрын
Yes kzbin.info/www/bejne/o6GpYpxvqMt4gJI
@sijumathew7039
@sijumathew7039 2 жыл бұрын
I just cannot separate the downloadstation, filestation, etc from the management UI. I just cannot block only the management-ui. Kind of useless for me with that all or nothing approach. But thanks
@noggan
@noggan 2 жыл бұрын
The only down side i can find is that it sends camera traffic through the firewall which means it will waste a bit of bandwidth, especially if you're using high-res cameras with h264. In my case it uses about 30 mbit constantly, but I have quite a few cameras.
@jadamsnz
@jadamsnz 2 жыл бұрын
If I understand it, and your comment, correctly, the firewall is on the Synology, not the pfSense box, so there would be no change in bandwidth use because the camera traffic was going directly to the Synology both before and after the firewall is activated. That's ignoring any VLAN management on the network, but that isn't changed by this procedure anyway.
@noggan
@noggan 2 жыл бұрын
@@jadamsnz that's true if they are on the same subnet, then we won't have to route through the firewall. And yes that won't waste any bandwidth. I myself don't use the firewall in the nas, instead it passes through my pfsense. Putting them on the same lan might be smarter. 😅👍
@richardk186
@richardk186 Жыл бұрын
Great video. Rather than use the 2 Synology ports separately as described, would it be possible or advantageous to setup Link Aggregation with the 2 ports and then create a vLAN for the Less Trusted Network?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Жыл бұрын
That should work as well.
@tuplas1877
@tuplas1877 2 жыл бұрын
This video came right on time. Just setting up some VLANs and was wondering how to set up my Synology. Do you know of a way to get Plex to use the second nic?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 жыл бұрын
It does automatically
@tuplas1877
@tuplas1877 2 жыл бұрын
@@LAWRENCESYSTEMS Now it's working. Had to visit the web interface on the new IP:port. From there disable and re-enable remote access for it to recognize the new IP. Also needed to restart chromecast.
@jasonperry6046
@jasonperry6046 2 жыл бұрын
Thank you.
@mickef5298
@mickef5298 2 жыл бұрын
Would I be secure if I dont forward any ports on my router to the Synology NAS. In other words, I would only have local access right?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 жыл бұрын
Not opening ports does up your security.
@droneforfun5384
@droneforfun5384 2 жыл бұрын
Sorry but you need to explain more basic and slow. I assume this tutorial is for beginners?
Synology Surveillance Station With Amcrest AI Advanced Detection
16:30
Lawrence Systems
Рет қаралды 44 М.
Basic Setup and Configuring pfsense Firewall Rules For Home
17:27
Lawrence Systems
Рет қаралды 365 М.
Touching Act of Kindness Brings Hope to the Homeless #shorts
00:18
Fabiosa Best Lifehacks
Рет қаралды 18 МЛН
Cute kitty gadgets 💛
00:24
TheSoul Music Family
Рет қаралды 21 МЛН
Bend The Impossible Bar Win $1,000
00:57
Stokes Twins
Рет қаралды 41 МЛН
这三姐弟太会藏了!#小丑#天使#路飞#家庭#搞笑
00:24
家庭搞笑日记
Рет қаралды 118 МЛН
My Synology NAS was ATTACKED!
8:01
WunderTech
Рет қаралды 51 М.
Massive Botnet Attacking Synology - how to protect your NAS
24:42
pfsense and Rules For IoT Devices with mDNS
17:08
Lawrence Systems
Рет қаралды 115 М.
How to Secure Your Synology NAS | Synology
26:56
Synology
Рет қаралды 35 М.
How to Configure Traffic Monitoring with ntopng on pfsense
16:18
Lawrence Systems
Рет қаралды 118 М.
I Built a NAS: One Year Later. EVERYTHING I Learned and the Mistakes
17:37
Jimmy Tries World
Рет қаралды 888 М.
How to Secure your Synology NAS (Best Practices)
29:56
WunderTech
Рет қаралды 20 М.
Touching Act of Kindness Brings Hope to the Homeless #shorts
00:18
Fabiosa Best Lifehacks
Рет қаралды 18 МЛН