In this article, you will discover 10 ways to enhance the security of your Synology NAS with Infomaniak.
Synology NAS servers have found increasing success with private individuals and are therefore the victims of numerous hacking attempts. In order to safeguard against this risk as much as possible, we strongly recommend that you take the time to secure your Synology NAS access.
10 ways to secure your Synology NAS access
To enhance the security of your Synology NAS:
1. Enable dual authentication
2. Choose a strong password
The password to access your Synology should be made up of at least 8 characters with upper case and lower case letters, numbers, and special characters.
3. Disable QuickConnect
When hosting your Synology server with Infomaniak, you will be given a free fixed public IP address which allows you to easily access your Synology server when traveling.
4. Change the default http (5000) and https (5001) ports of the DSM
The port number must be between 1024 and 65535.
5. Enable https connection and connection redirection to https
6. Enable DoS protection
7. Disable DSM integration in iFrame
8. Disable IPv6
For now, the Synology firewall does not handle IPv6.
9. Configure your Synology firewall
To configure the firewall of your Synology, open the Control panel and from the Security menu, click on the Firewall tab.
Follow these steps in order to enhance the security of your Synology:
9.1 Authorize the DSM http and https ports
- Click on the Create button
- Under Ports, check the two boxes corresponding to the Synology Management Interface (http & https)
- Under IP Source, you can limit access to Synology from an area or a fixed IP address if you have one
- Click on the Save button
Define a restrictive policy for the default firewall
- Check the Refuse access box
- Click on the Save button
Now, only http and https access to the Synology DSM will be authorized. You will have to manually authorize the ports of the applications you wish to use.
10. Additional security recommendations
- Always use the latest version of DiskStation Manager (DSM)
- Regularly update the applications you use
- Uninstall the application packages you do not use and delete the corresponding Synology firewall authorisations
- Consult the journal centre to detect potential anomalies/alerts/errors
- Enable email or sms notifications for the important alerts (Control panel > Notification >…)
For more security: the Synology VPN server
You must be aware that even when following all of the security recommendations in this article, all Synology services remain accessible via a simple web browser. This means that if Synology applications have faults, these can be exploited through the internet.
We will see in another article how to guard against this last possibility by restricting your Synology NAS access to the one VPN service.
***
The kMail app is available in a beta version to manage Infomaniak addresses on your mobile
Thursday April 13th, 2023
Premium Support, our 24/7 assistance solution for companies and government agencies
Thursday March 23rd, 2023
You must be logged in to post a comment.