No video

How to Secure Your Unraid Server 🖥️ Unraid Security Best Practices

  Рет қаралды 25,969

The Bearded Tech Guy

The Bearded Tech Guy

Күн бұрын

Пікірлер: 57
@BeardedTechGuy
@BeardedTechGuy 3 жыл бұрын
What other steps are you taking to secure your Unraid storage server? Let me know below!
@topytopy
@topytopy 2 жыл бұрын
Hi TBTG! I have been trying to harden the SMB configuration with the following improvements: Null passwords are disabled, SMB signing is mandatory, SMB encryption is mandatory, the minimum protocol version for supported is SMB3_11 for all communications and the ntlm auth is configured to be ntlmv2-only. I have not yet found a way to configure this correctly via the web interface as the "Samba extra configuration" field is confusing. If you could create an additional video about this, that would be exceptionally helpful! Thanks.
@alice20001
@alice20001 Ай бұрын
EPIC! This is phenomenal. It's both general good security practices as well as high level hardening that just about every video misses! Outstanding!
@BeardedTechGuy
@BeardedTechGuy Ай бұрын
Glad you liked it!
@thebaldfox
@thebaldfox 3 жыл бұрын
Great video, logical and well laid out. I just subbed... would love to see a walk through or a breakdown of reverse proxy, the pros and cons / vulnerabilities in a similar manner, rather than just the usual this is how to install it in docker and add cloudflare :)
@BeardedTechGuy
@BeardedTechGuy 3 жыл бұрын
Glad you liked the video and thank you for subscribing! I'll keep your suggestion in mind for an upcoming video, thanks for the input!
@arnoldfriend8197
@arnoldfriend8197 3 жыл бұрын
Great video!!
@BeardedTechGuy
@BeardedTechGuy 3 жыл бұрын
Glad you enjoyed it
@jpulley
@jpulley 3 жыл бұрын
Very helpful, subbed!
@BeardedTechGuy
@BeardedTechGuy 3 жыл бұрын
Glad you found the video and thank you for subscribing!
@gamer1xbox360
@gamer1xbox360 2 жыл бұрын
Great tutorial and well explained, thank you
@BeardedTechGuy
@BeardedTechGuy 2 жыл бұрын
I'm glad you found it helpful!
@roberts_irregular_random_rec
@roberts_irregular_random_rec 3 жыл бұрын
At 7:06, hard to understand what you are saying: ". . . for this setting, I recommend setting to yes and ????" Nice video - thank you for creating this.
@BeardedTechGuy
@BeardedTechGuy 3 жыл бұрын
Oh wow, guess my noise gate caught me there. I recommend "Yes (Hidden)" That's the problem with listening to my own videos, my ears fill in gaps I know no matter how many times I listen to it. Thanks for catching that!
@ZombieTechie
@ZombieTechie 6 ай бұрын
Love the channel name!
@RagnarRipper
@RagnarRipper 3 жыл бұрын
That was a great video! Watched it just to make sure and I'm pretty proud that I did all the things already :)
@BeardedTechGuy
@BeardedTechGuy 3 жыл бұрын
Glad you liked the video!!
@xxxxxxsauron
@xxxxxxsauron Жыл бұрын
thanks. please make a total noob video on everything unraid.. with SMB explained also how to use torrent and prowlarr with openvpn. how to setup plex with hardware transcoding
@daz7748
@daz7748 3 жыл бұрын
Very well explained, thank you!
@BeardedTechGuy
@BeardedTechGuy 3 жыл бұрын
Glad you found the video helpful!
@thenanook
@thenanook 3 жыл бұрын
good info, liked and subscribed
@BeardedTechGuy
@BeardedTechGuy 3 жыл бұрын
Glad you liked the video!
@Richardj410
@Richardj410 2 жыл бұрын
Thanks, it's sinking in slowly.
@DarkwaterV2
@DarkwaterV2 Жыл бұрын
Thanks a lot!
@BeardedTechGuy
@BeardedTechGuy Жыл бұрын
You're welcome!!
@cd9954
@cd9954 7 ай бұрын
Good info thanks. Since you keep that port for Plex open, isn’t that a vulnerability? Do you have docker running? Fail2ban?
@whizadree
@whizadree 2 жыл бұрын
I wouldnt do DMZ
@sidewind131258
@sidewind131258 Жыл бұрын
I was following along and making changes here and there as I thought I needed them, and when I was finished with "Turn on Unraid notifications" I found out that I suddently had explanations folded out everywhere, do you have any idea on where to turn those off ? I run version 6.11.5
@BeardedTechGuy
@BeardedTechGuy Жыл бұрын
In the top right hand corner there should be a little question mark in a circle. If it has a line under it, that means it's enabled / selected witch auto expands all the tips. If you want that off, it should not have a line under it. Here is what it looks like when off (top image) and on (bottom image): imgur.com/a/rbFW0EF
@TechySpeaking
@TechySpeaking 3 жыл бұрын
first
@BeardedTechGuy
@BeardedTechGuy 3 жыл бұрын
Almost!
@johnmarkzimm
@johnmarkzimm 2 жыл бұрын
Do you install anti virus software on your Unraid server... the only one I see is calmav.
@BeardedTechGuy
@BeardedTechGuy 2 жыл бұрын
Great question! That honestly never crossed my mind. Are you asking for the files stored on the shares of Unraid or for the Unraid OS / storage itself?
@onestopviewfiles
@onestopviewfiles 3 жыл бұрын
12:12 so are plex ports on 32400 that are port forwarded ok? just don't forward any common ports like port 80?
@BeardedTechGuy
@BeardedTechGuy 3 жыл бұрын
So realistically, any port forwarding (including Plex) introduces risk to your network. For me, I "trust" Plex enough to be served traffic from the Internet so I port forward 32400 for it. Port 80 is usually used for HTTP traffic which means it is not encrypted and sent in the clear, so anyone who can see the traffic can see the contents. Because of this, it is recommended to not use and instead use HTTPS over 443 with a certificate to help protect the traffic - IF you need web browser traffic forwarded to a device in your home network. Even though HTTPS is encrypted, anyone can still access the webpage so that server could still be hacked.
@onestopviewfiles
@onestopviewfiles 3 жыл бұрын
@@BeardedTechGuy thanks dude, so if I just only have the plex port forwarded, and thats it, then I should be ok?
@BeardedTechGuy
@BeardedTechGuy 3 жыл бұрын
If you only have 32400 being forwarded then that would be the only traffic sourced from the Internet that would get forwarded into your home network. At that point, as long as your Plex server isn't vulnerable for any known attacks (always keep it up to date to help protect it), then your risk would be minimal.
@ajugland
@ajugland 2 жыл бұрын
Still dont know how my PC always prompt for credentials even though its a public share
@BeardedTechGuy
@BeardedTechGuy 2 жыл бұрын
Hmm that's a weird one. You could check the credential store and see if a account is saved for it. Or if its not too destructive I'd remove the share and readd it to see what happens.
@ATWPussyCat
@ATWPussyCat 2 жыл бұрын
How can I prevent the password from being reset (as described in the password recovery, edit the file under /boot/config/shadow)? If someone steals my entire server, they have all the data. Is there a clever way to encrypt the data yourself?
@BeardedTechGuy
@BeardedTechGuy 2 жыл бұрын
Great question! I tried to do some searching but couldn't really find anything. What seems like your best option would be to do disk encryption. My understanding is that the encryption password cannot be reset. I'm not sure if it's required every time on power up though. If it's saved in Unraid to mount the share and the saved encryption key is not wiped on password reset it really wouldn't protect against the entire server being stolen just the disks themselves.
@Vcen7
@Vcen7 2 жыл бұрын
@@BeardedTechGuy Password is required on each reboot, but it does protect against robbers with strong backs.
@BeardedTechGuy
@BeardedTechGuy 2 жыл бұрын
Good to know! Thank you for sharing
@seamydobbsno1
@seamydobbsno1 3 жыл бұрын
Are you bound to the beard for the lifetime of your channel now?
@BeardedTechGuy
@BeardedTechGuy 3 жыл бұрын
One does not choose The Beard, The Beard chooses the one.
@seamydobbsno1
@seamydobbsno1 3 жыл бұрын
@@BeardedTechGuy My understanding of the truth is that I am talking to the beard 🙌
@Calamity_Jack
@Calamity_Jack 2 жыл бұрын
Do you need SSH if you're using the My Servers feature?
@BeardedTechGuy
@BeardedTechGuy 2 жыл бұрын
My understanding is that you would not need SSH for the My Servers feature, so it should be able to be turned off if you don't want even local (on network) remote access to the server.
@Calamity_Jack
@Calamity_Jack 2 жыл бұрын
@@BeardedTechGuy Thanks for that. I do remotely access my server via my PC (local, on the same intranet) to manage it, so would I need to leave SSH enabled to do that? Or does My Servers bypass all of that and allow me to remotely admin my server via browser on my PC?
@BeardedTechGuy
@BeardedTechGuy 2 жыл бұрын
SSH is used for the CLI access. For GUI either local or through "My Servers" uses HTTPs. If you do not need CLI access to unraid locally you should be able to disable SSH without impact to My Servers.
@Calamity_Jack
@Calamity_Jack 2 жыл бұрын
@@BeardedTechGuy Awesome, thx for clarifying!
@Redneckrampage
@Redneckrampage 2 жыл бұрын
Secure unraid don't don't mention about unraid SSL
@GrandmaHatesTech
@GrandmaHatesTech 3 жыл бұрын
I have a 200 pound dog to make sure nobody accesses my computer Grrrrr
@BeardedTechGuy
@BeardedTechGuy 3 жыл бұрын
Not sure why but I just imagined Snoopy sitting on a laptop wearing the typical "hacker gear" lol
@activate_filmscore
@activate_filmscore 21 күн бұрын
🛑🛑🛑That’s not what ppl are clicking this for …. Ppl want volume and pool encryption…. Answer is unfair can’t do it … true nas can🛑🛑🛑
@jbrown70579
@jbrown70579 3 жыл бұрын
Really trying to monetize this video? 10 ads in 15 mins? Seriously? Thumbs down.
@BeardedTechGuy
@BeardedTechGuy 3 жыл бұрын
I think I'm getting ripped off! I only put 3 ad breaks in for the 15 minute video and KZbin very rarely uses all of them ¯\_(ツ)_/¯ imgur.com/a/KmawmsA
Setting up Shares on Unraid 6.9 for Best Performance
14:19
Spaceinvader One
Рет қаралды 94 М.
Intel 13th Gen + Unraid + Plex = OMG4K!
11:30
Byte My Bits
Рет қаралды 67 М.
Gli occhiali da sole non mi hanno coperto! 😎
00:13
Senza Limiti
Рет қаралды 16 МЛН
Logo Matching Challenge with Alfredo Larin Family! 👍
00:36
BigSchool
Рет қаралды 20 МЛН
Алексей Щербаков разнес ВДВшников
00:47
Downsizing my Home Lab to a SINGLE PC
17:56
Raid Owl
Рет қаралды 335 М.
UNRAID Vs TRUENAS: Which Home Server NAS Is Best?
48:13
Digital Spaceport
Рет қаралды 157 М.
How to Migrate Unraid from One Server to Another
9:07
Spaceinvader One
Рет қаралды 39 М.
How does fiber internet work? 0ms ping!
20:37
Snazzy Labs
Рет қаралды 1,3 МЛН
Save Terabytes of Disk Space Using H265 & Tdarr
35:39
Spaceinvader One
Рет қаралды 176 М.
Self-Hosting Security Guide for your HomeLab
18:43
Techno Tim
Рет қаралды 355 М.
I tried Unraid for the FIRST time in 2024
21:05
Techno Tim
Рет қаралды 139 М.
Unraid Shares in Depth - PT1 Windows and SMB - Problems & Solutions
29:04
Spaceinvader One
Рет қаралды 114 М.
You're running Pi-Hole wrong! Setting up your own Recursive DNS Server!
18:02
Gli occhiali da sole non mi hanno coperto! 😎
00:13
Senza Limiti
Рет қаралды 16 МЛН