{"id":21908,"date":"2026-10-11T23:59:10","date_gmt":"2026-10-11T15:59:10","guid":{"rendered":"https:\/\/synopower.club\/?post_type=docs&#038;p=21908"},"modified":"2026-10-11T23:59:16","modified_gmt":"2026-10-11T15:59:16","password":"","slug":"synology-nas-security-public-website","status":"publish","type":"docs","link":"https:\/\/synopower.club\/it\/docs\/synology-nas-security-public-website\/","title":{"rendered":"Sicurezza NAS per un sito web pubblico: i 5 livelli che utilizziamo su Synology"},"content":{"rendered":"<p class=\"wp-block-paragraph\">NAS security is usually described as a list of switches inside DSM. For a NAS that only holds family photos, that list is enough. Ours does something riskier: SynoPower Club, a store that takes payments in 16 languages, is served from a Synology NAS in our own rack, so every scanner and botnet on the internet can knock on the door. One setting was never going to be enough NAS security for that. This NAS Hosting 101 article walks through the five layers a request crosses before it reaches WordPress, what each layer caught in real incidents during 2026, and the times a layer hurt us instead of the attacker.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Punto SynoPower Club:<\/strong> I worked on the support side of Synology for years, and the compromised machines I saw were almost never beaten by something clever. They had the default admin account still enabled, a management port forwarded to the internet, and no second factor. Good NAS security is mostly boring work done in the right order. What surprised me after we started hosting our own store is how much of the job moves outside the NAS. Most of the traffic we refuse today is turned away before it ever touches our line.<\/p>\n<\/blockquote>\n\n\n\n<h2 id=\"what-nas-security-means-once-the-nas-hosts-a-website\" class=\"wp-block-heading\">What NAS Security Means Once the NAS Hosts a Website<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A private NAS has one job in a security sense: keep strangers out of the login page. A NAS that hosts a public website has the opposite problem. Strangers are the customers, and thousands of them must get in every day without an account. The question changes from who may connect to what a connection is allowed to ask for.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That is why we stopped thinking about NAS security as a product feature and started drawing it as a path. A request for our shop passes five points, and each one can refuse it:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>The edge.<\/strong> Cloudflare receives every request first and answers most of them from its own cache.<\/li>\n\n\n\n<li><strong>The router.<\/strong> A Synology router inspects what Cloudflare passes on and forwards only the ports we need.<\/li>\n\n\n\n<li><strong>The front NAS.<\/strong> A DSM machine terminates TLS and acts as reverse proxy and mail server.<\/li>\n\n\n\n<li><strong>The Virtual DSM.<\/strong> WordPress runs in a container inside its own Virtual DSM instance, apart from everything else.<\/li>\n\n\n\n<li><strong>The application.<\/strong> WordPress itself decides what a visitor may do on a form or a login page.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">No single layer is trusted to be right. Each one is there for the day the layer in front of it is wrong, misconfigured, or simply bypassed.<\/p>\n\n\n\n<h2 id=\"layer-1-cloudflare-refuses-most-attacks-before-they-reach-us\" class=\"wp-block-heading\">Layer 1: Cloudflare Refuses Most Attacks Before They Reach Us<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Good NAS security starts somewhere that is not the NAS. The cheapest request to defend against is the one that never arrives. In the 24 hours before we wrote this, Cloudflare handled 78,690 requests for our domain. It answered 57,620 of them from its cache, stopped 5,590 as unwanted, and sent only 15,470 on to our origin. Four out of five requests never used a single CPU cycle on the NAS.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"2560\" height=\"499\" sizes=\"(max-width: 2560px) 100vw, 2560px\" src=\"https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/cloudflare-security-analytics-mitigated-requests-scaled.webp\" alt=\"Cloudflare security analytics for a Synology-hosted store, the first NAS security layer, showing requests mitigated, served from cache and served by origin\" class=\"wp-image-21906\" srcset=\"https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/cloudflare-security-analytics-mitigated-requests-scaled.webp 2560w, https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/cloudflare-security-analytics-mitigated-requests-300x58.webp 300w, https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/cloudflare-security-analytics-mitigated-requests-1024x200.webp 1024w, https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/cloudflare-security-analytics-mitigated-requests-768x150.webp 768w, https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/cloudflare-security-analytics-mitigated-requests-1536x299.webp 1536w, https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/cloudflare-security-analytics-mitigated-requests-2048x399.webp 2048w, https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/cloudflare-security-analytics-mitigated-requests-18x4.webp 18w, https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/cloudflare-security-analytics-mitigated-requests-400x78.webp 400w, https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/cloudflare-security-analytics-mitigated-requests-1000x195.webp 1000w\" \/><figcaption class=\"wp-element-caption\">One ordinary day in October 2026. The yellow line is traffic answered from the Cloudflare cache, the blue line is what reached our NAS, and the pink line is what Cloudflare refused.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">We are on the Pro plan and run 15 custom firewall rules plus two rate limits. Every one of them exists because of a specific bad day. Three examples show the pattern:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Webshell hunters, 20 July.<\/strong> In 17 hours we logged 950 probes for 535 different PHP file names from 14 addresses. Blocking addresses could not keep up, so we turned the logic around: only the handful of PHP entry points WordPress really uses are allowed, and every other one is refused at the edge.<\/li>\n\n\n\n<li><strong>Credential scanners, 29 August.<\/strong> A wave from cloud hosting networks asked for configuration and secret files more than 1,400 times. None existed, but each miss made WordPress build a full error page, the load average reached 46 and the container had to be restarted. Those paths are now blocked outright, and unverified traffic from the large cloud networks gets a browser challenge.<\/li>\n\n\n\n<li><strong>An add-to-cart botnet, 31 August.<\/strong> Within an hour, 258 add-to-cart requests arrived from almost as many different addresses, about one request each, so there was nothing to block by address. A managed challenge on that one action stopped it, and real browsers pass it without noticing.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Cloudflare Turnstile covers the forms the firewall cannot judge: registration, password reset, comments and the contact form. The account that controls all of this, and the one at our domain registrar, both require a second factor. An attacker who can change your DNS does not need to break your NAS.<\/p>\n\n\n\n<h2 id=\"layer-2-threat-prevention-on-the-synology-router\" class=\"wp-block-heading\">Layer 2: Threat Prevention on the Synology Router<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Whatever Cloudflare lets through arrives at a Synology router running SRM, the second NAS security layer. This is the layer that was in the original note for this article: <em>Threat Prevention blocks another wave<\/em>. It is an intrusion prevention system that compares packets with known attack signatures, and ours is set to drop high-severity matches automatically instead of merely logging them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On 2 August 2026 one address fired 116 attempts at a PHP flaw that only affects Windows servers. It could never have worked against us, and that is the point of the story: Threat Prevention dropped every attempt, and when we searched the web server logs afterwards the address was not there at all. The attack ended at the router.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"2404\" height=\"966\" sizes=\"(max-width: 2404px) 100vw, 2404px\" src=\"https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/synology-router-threat-prevention-map.webp\" alt=\"Synology router Threat Prevention map showing the sources of high, medium and low severity events over seven days, the second NAS security layer\" class=\"wp-image-21909\" srcset=\"https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/synology-router-threat-prevention-map.webp 2404w, https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/synology-router-threat-prevention-map-300x121.webp 300w, https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/synology-router-threat-prevention-map-1024x411.webp 1024w, https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/synology-router-threat-prevention-map-768x309.webp 768w, https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/synology-router-threat-prevention-map-1536x617.webp 1536w, https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/synology-router-threat-prevention-map-2048x823.webp 2048w, https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/synology-router-threat-prevention-map-18x7.webp 18w, https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/synology-router-threat-prevention-map-400x161.webp 400w, https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/synology-router-threat-prevention-map-1000x402.webp 1000w\" \/><figcaption class=\"wp-element-caption\">Seven days of Threat Prevention events on our router in October 2026, plotted by source. Red marks are high severity, and those packets are dropped automatically.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Three plainer settings on the same box do as much for NAS security as the inspection engine does:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Only the necessary ports are forwarded.<\/strong> Web and mail ports go to the front NAS. The DSM management ports and SSH are not forwarded anywhere.<\/li>\n\n\n\n<li><strong>Country rules in the firewall.<\/strong> A short list of regions we do not sell to is refused before any application sees the packet.<\/li>\n\n\n\n<li><strong>Safe Access.<\/strong> DNS and web filtering stop machines inside the network from talking to known malicious domains, which matters on the day something inside is already infected.<\/li>\n<\/ul>\n\n\n\n<h2 id=\"layer-3-nas-security-inside-dsm-from-2fa-to-auto-block\" class=\"wp-block-heading\">Layer 3: NAS Security Inside DSM, From 2FA to Auto Block<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The front NAS is the first Synology system an outside packet can reach, so this is where classic NAS security advice applies in full. Our settings are deliberately unoriginal:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>The default accounts are disabled.<\/strong> Entrambi <code>admin<\/code> e <code>guest<\/code> are switched off. Every automated login attack starts with those two names.<\/li>\n\n\n\n<li><strong>Administrators cannot sign in with a password alone.<\/strong> Two-factor authentication is enforced for the whole administrators group, and Adaptive MFA asks for extra proof when a sign-in looks unusual.<\/li>\n\n\n\n<li><strong>Auto Block is on.<\/strong> Ten failed logins within five minutes block the source address, and the block does not expire by itself.<\/li>\n\n\n\n<li><strong>The DSM firewall is enabled<\/strong> on top of the router rules, so a mistake on one device is not a hole in both.<\/li>\n\n\n\n<li><strong>Security updates install themselves<\/strong> on this machine. On the Virtual DSM that runs the shop we are only notified, and we update by hand after taking a snapshot.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"1540\" height=\"872\" sizes=\"(max-width: 1540px) 100vw, 1540px\" src=\"https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/dsm-enforce-2fa-administrators-adaptive-mfa.webp\" alt=\"DSM Control Panel Security Account tab with 2-factor authentication enforced for the administrators group and Adaptive MFA enabled\" class=\"wp-image-21907\" srcset=\"https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/dsm-enforce-2fa-administrators-adaptive-mfa.webp 1540w, https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/dsm-enforce-2fa-administrators-adaptive-mfa-300x170.webp 300w, https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/dsm-enforce-2fa-administrators-adaptive-mfa-1024x580.webp 1024w, https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/dsm-enforce-2fa-administrators-adaptive-mfa-768x435.webp 768w, https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/dsm-enforce-2fa-administrators-adaptive-mfa-1536x870.webp 1536w, https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/dsm-enforce-2fa-administrators-adaptive-mfa-18x10.webp 18w, https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/dsm-enforce-2fa-administrators-adaptive-mfa-400x226.webp 400w, https:\/\/synopower.club\/wp-content\/uploads\/2026\/10\/dsm-enforce-2fa-administrators-adaptive-mfa-1000x566.webp 1000w\" \/><figcaption class=\"wp-element-caption\">Control Panel, Security, Account on the front NAS. Enforcing the second factor for the group means a new administrator cannot forget to enable it, which is NAS security that survives staff changes.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Two habits matter to NAS security as much as the switches. We reach DSM from outside through QuickConnect or not at all, which is why no management port needs to be open. And temporary helpers get temporary accounts: when a contractor or an AI agent needs administrator access, we create a named account, let the work finish, and disable it the same day.<\/p>\n\n\n\n<h2 id=\"layer-4-a-virtual-dsm-that-contains-the-damage\" class=\"wp-block-heading\">Layer 4: A Virtual DSM That Contains the Damage<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">WordPress does not run on the front NAS. It runs in a container inside a Virtual DSM, a complete second copy of DSM hosted by Virtual Machine Manager. Mail, the reverse proxy and the shop therefore live in separate systems with separate accounts and separate storage.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Isolation is the part of NAS security that does not try to prevent a break-in. It limits what a break-in is worth. If a WordPress plugin is ever compromised, the attacker lands in a container with a memory limit, inside a virtual machine that holds no mailboxes and no backups. And because the whole machine is a single file to Virtual Machine Manager, a snapshot before every risky change takes seconds and rolling back takes a few minutes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Virtual Machine Manager includes one Virtual DSM instance free of charge on supported models, which is enough to try this layout. Further instances need a license each.<\/p>\n\n\n\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-is-layout-a221f4eb wp-block-buttons-is-layout-flex\" style=\"border-style:none;border-width:0px;border-radius:0px;margin-top:var(--wp--preset--spacing--50);margin-bottom:var(--wp--preset--spacing--50);padding-top:var(--wp--preset--spacing--40);padding-right:0;padding-bottom:var(--wp--preset--spacing--40);padding-left:0\">\n<div class=\"wp-block-button is-style-fill\"><a class=\"wp-block-button__link has-palette-color-4-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-element-button\" href=\"https:\/\/synopower.club\/it\/virtual-dsm-vdsm-license-pack\/\" style=\"border-radius:15px\" target=\"_blank\" rel=\"noreferrer noopener\">Get a Virtual DSM license<\/a><\/div>\n<\/div>\n\n\n\n<h2 id=\"layer-5-what-wordpress-still-has-to-do-itself\" class=\"wp-block-heading\">Layer 5: What WordPress Still Has to Do Itself<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The outer NAS security layers judge packets and requests. Only the application knows what a request means, so a few defences have to live in WordPress:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>A second factor for every administrator login<\/strong>, the same rule as in DSM.<\/li>\n\n\n\n<li><strong>Quiet limits on password resets.<\/strong> Repeated reset requests for one account are dropped without an error message, because a helpful error tells an attacker the account exists.<\/li>\n\n\n\n<li><strong>No user list for strangers.<\/strong> The standard ways of listing WordPress user names are closed.<\/li>\n\n\n\n<li><strong>Tor is refused on forms.<\/strong> In September somebody used our contact form to flood other people with confirmation emails, every submission arriving through Tor. Reading the site over Tor still works. Submitting a form does not.<\/li>\n\n\n\n<li><strong>A cheap error page.<\/strong> A request for something that does not exist gets a one-kilobyte answer instead of a full themed page of 148 kilobytes.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The Tor incident has its own write-up: <a href=\"\/it\/docs\/email-bombing-contact-form-synology-nas\/\">Invio massiccio di email tramite modulo di contatto<\/a>.<\/p>\n\n\n\n<h2 id=\"adding-nas-security-in-4-steps-outside-in\" class=\"wp-block-heading\">Adding NAS Security in 4 Steps, Outside In<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you are starting from a NAS with default settings, the order of your NAS security work matters more than the tools. Work from the outside in, and test the site after each step.<\/p>\n\n\n<div id=\"rank-math-howto\" class=\"rank-math-block\" >\n<div class=\"rank-math-howto-description\">\n\n<\/div>\n\n<div class=\"rank-math-steps\">\n<div id=\"step-1\" class=\"rank-math-step\">\n<h3 class=\"rank-math-step-title\">Put a proxy in front of the site<\/h3>\n<div class=\"rank-math-step-content\"><p>Move the DNS of your domain to Cloudflare and switch the records for the website to proxied. Turn on Always Use HTTPS, add Turnstile to your login and contact forms, and block the paths your site never uses. From this moment most attacks are answered by Cloudflare and not by your NAS.<\/p>\n<\/div>\n<\/div>\n<div id=\"step-2\" class=\"rank-math-step\">\n<h3 class=\"rank-math-step-title\">Turn on Threat Prevention and forward only what you need<\/h3>\n<div class=\"rank-math-step-content\"><p>On a Synology router install Threat Prevention and let it drop high severity events automatically. Then open the port forwarding list and delete everything except the web ports and, if you run mail, the mail ports. Never forward the DSM management ports or SSH.<\/p>\n<\/div>\n<\/div>\n<div id=\"step-3\" class=\"rank-math-step\">\n<h3 class=\"rank-math-step-title\">Lock down the DSM administrator accounts<\/h3>\n<div class=\"rank-math-step-content\"><p>In Control Panel disable the admin and guest accounts and create a named administrator. Under Security, Account enforce 2-factor authentication for the administrators group. Under Security, Protection enable Auto Block. Enable the DSM firewall as well.<\/p>\n<\/div>\n<\/div>\n<div id=\"step-4\" class=\"rank-math-step\">\n<h3 class=\"rank-math-step-title\">Schedule updates, a scan and an offsite backup<\/h3>\n<div class=\"rank-math-step-content\"><p>Let DSM install security updates automatically, or set a reminder if you prefer to update by hand after a snapshot. Run Security Advisor and clear its findings. Finally make sure one copy of the whole system leaves the building on a schedule.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n\n\n\n\n\n\n<p class=\"wp-block-paragraph\">A fifth step belongs to anyone who finishes the first four: restrict the web ports at the router to the address ranges Cloudflare publishes. It is the piece of NAS security most often left for later. Until that is done, a proxy is a suggestion. Anyone who learns the real address of the line can walk around it and meet only the inner layers.<\/p>\n\n\n\n<h2 id=\"when-a-nas-security-rule-hurts-you-instead\" class=\"wp-block-heading\">When a NAS Security Rule Hurts You Instead<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Every rule that stops an attacker can stop a customer, and the failure is silent. These are the three times our own NAS security setup cost us something.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In July a rule aimed at crawlers also blocked the checker Google uses to review shopping listings, and 39 product listings were disapproved before we connected the two events. Since then every bot rule makes an explicit exception for verified search crawlers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In September a business customer in the United States tried to pay four times over two days and failed each time without an error on either side. His company routes all web traffic through a cloud security gateway, so to our firewall he looked like the scanners from the August wave and got a challenge in the middle of checkout. Corporate buyers often arrive from the same cloud networks that attackers rent. We narrowed the rule so that people who are already shopping are left alone.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And the Threat Prevention engine that performed so well on 2 August stopped passing outbound traffic for our mail server after that same burst. Mail queued until the router was restarted. An inspection engine in the path is one more thing that can fail, and when ours failed, it failed closed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The lesson for NAS security is not to remove layers. It is to write down why each rule exists, look at what it blocked in its first week, and prefer a challenge to a block whenever a real person might be on the other end.<\/p>\n\n\n\n<h2 id=\"backups-are-the-layer-that-works-after-the-others-fail\" class=\"wp-block-heading\">Backups Are the Layer That Works After the Others Fail<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">No amount of NAS security makes recovery optional. Hardware fails, updates go wrong, and an administrator at one in the morning is more dangerous than most botnets. We keep three kinds of copy: snapshots on the NAS for quick rollback, a scheduled export of the complete virtual machine that is synchronised to cloud storage, and a separate offsite backup of the data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The virtual machine export is described step by step in <a href=\"\/it\/docs\/vmm-backup-google-drive-cloud-sync\/\">VMM backup to Google Drive<\/a>, and the cluster that hosts all of it in <a href=\"\/it\/docs\/synology-virtual-machine-cluster-vmm-pro\/\">our 3-node VMM Pro setup<\/a>.<\/p>\n\n\n\n<h2 id=\"limits-of-this-nas-security-setup\" class=\"wp-block-heading\">Limits of This NAS Security Setup<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This is one small company describing what it runs, not a standard. A few honest limits:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our NAS security depends on Cloudflare. If their network has a bad day, so do we, and the paid plan is part of the monthly cost of the site.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It was built by reacting. Most of our rules were written the day after an incident. A larger team would have done threat modelling first, and would have found some of these holes before an attacker did.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NAS security needs maintenance. Rules that list specific paths or networks go stale, and a rule nobody remembers is a future outage. We review the list whenever the site structure changes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And it protects a shop, not a bank. If you store health records or card numbers on a NAS, you need more than this article, starting with a professional review.<\/p>\n\n\n\n<h2 id=\"frequently-asked-questions\" class=\"wp-block-heading\">Domande frequenti<\/h2>\n\n\n<div id=\"rank-math-faq\" class=\"rank-math-block\">\n<div class=\"rank-math-list\">\n<div id=\"faq-1\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question\">Is it safe to host a public website on a Synology NAS?<\/h3>\n<div class=\"rank-math-answer\">\n\n<p>It can be, if the NAS is not the only line of defence. Good NAS security puts the work in layers. Put a proxy such as Cloudflare in front, forward only the web ports, keep management access off the internet and run the site in a container or a Virtual DSM so that a compromised site cannot reach your other data.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-2\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question\">What is the most important NAS security setting in DSM?<\/h3>\n<div class=\"rank-math-answer\">\n\n<p>Disable the default admin account and enforce 2-factor authentication for every administrator. Most successful attacks on a NAS are logins with a guessed or leaked password, and a second factor defeats those even when the password is known.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-3\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question\">What does Threat Prevention on a Synology router do?<\/h3>\n<div class=\"rank-math-answer\">\n\n<p>It inspects traffic passing through the router and compares it with signatures of known attacks. Events are graded by severity, and the router can drop high severity packets automatically. It runs on Synology routers with SRM.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-4\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question\">Do I still need NAS security settings if I use Cloudflare?<\/h3>\n<div class=\"rank-math-answer\">\n\n<p>Yes. Cloudflare only sees traffic that is sent through it. Anything that reaches your line directly, and anything that starts inside your network, never meets those rules. The router and DSM settings are what cover those cases.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-5\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question\">Should I forward port 5000 or 5001 to reach DSM remotely?<\/h3>\n<div class=\"rank-math-answer\">\n\n<p>No. Leave the DSM management ports closed to the internet. Use QuickConnect or a VPN when you need to reach DSM from outside. An open management port is found by scanners within hours and attacked continuously.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-6\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question\">How does Auto Block work in DSM?<\/h3>\n<div class=\"rank-math-answer\">\n\n<p>Auto Block counts failed sign-in attempts per source address. When the count passes the limit you set within the time window you set, DSM refuses further connections from that address. We use ten attempts in five minutes with no expiry.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-7\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question\">Can a NAS security rule block real customers?<\/h3>\n<div class=\"rank-math-answer\">\n\n<p>Yes, and it does so silently. Rules based on network or country can catch buyers behind corporate security gateways or travellers abroad. Prefer a challenge to a hard block for anything a person might trigger, and review what a new rule stopped during its first week.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-8\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question\">Does NAS security replace backups?<\/h3>\n<div class=\"rank-math-answer\">\n\n<p>No. Security lowers the chance of an incident and backups decide what an incident costs. Keep snapshots for quick rollback and at least one copy outside the building, and test a restore before you need one.<\/p>\n\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n\n\n<h2 id=\"references-and-video-walkthroughs\" class=\"wp-block-heading\">Riferimenti e video dimostrativi<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/kb.synology.com\/en-global\/DSM\/tutorial\/How_to_add_extra_security_to_your_Synology_NAS\" target=\"_blank\" rel=\"noreferrer noopener\">Synology: how to add extra NAS security<\/a>, the official checklist for accounts, firewall and updates.<\/li>\n\n\n\n<li><a href=\"https:\/\/kb.synology.com\/en-global\/SRM\/help\/ThreatPrevention\/threatprevention_desc\" target=\"_blank\" rel=\"noreferrer noopener\">Synology SRM Threat Prevention help<\/a>, describing severity levels and the automatic drop policy.<\/li>\n\n\n\n<li><a href=\"https:\/\/kb.synology.com\/en-global\/DSM\/help\/DSM\/SecureSignIn\/2factor_authentication\" target=\"_blank\" rel=\"noreferrer noopener\">Synology DSM 2-factor authentication help<\/a>, including how to enforce it for a group.<\/li>\n\n\n\n<li><a href=\"https:\/\/developers.cloudflare.com\/waf\/custom-rules\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Cloudflare WAF custom rules<\/a>, the rule language behind the edge layer.<\/li>\n\n\n\n<li><a href=\"https:\/\/www.cloudflare.com\/ips\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Cloudflare IP ranges<\/a>, the list to allow at your router when you lock the origin.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">These Synology videos cover the DSM side of NAS security, from the general checklist to the second factor and user permissions.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe title=\"How to Secure Your Synology NAS | Synology SPOT\" width=\"1200\" height=\"675\" src=\"https:\/\/www.youtube.com\/embed\/bATSGcrQ_m4?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><figcaption class=\"wp-element-caption\">How to Secure Your Synology NAS<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe title=\"How to enable 2-Factor Authentication in DSM? | Synology\" width=\"1200\" height=\"675\" src=\"https:\/\/www.youtube.com\/embed\/oLbVhRR0hfI?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><figcaption class=\"wp-element-caption\">How to enable 2-Factor Authentication in DSM<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe title=\"How to Manage User Permissions on Your Synology NAS | Synology\" width=\"1200\" height=\"675\" src=\"https:\/\/www.youtube.com\/embed\/LihsU5hHm3k?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><figcaption class=\"wp-element-caption\">How to Manage User Permissions on Your Synology NAS<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Altri articoli di questa serie sull&#039;hosting aziendale su un NAS: <a href=\"\/it\/docs\/synology-mailplus-smtp-relay-resend\/\">fixing rejected mail with an SMTP relay<\/a>. Want to separate your own services the way we do? Start with <a href=\"https:\/\/synopower.club\/it\/virtual-dsm-vdsm-license-pack\/\" target=\"_blank\" rel=\"noreferrer noopener\">una licenza Virtual DSM<\/a>, oppure sfoglia tutte le licenze su <a href=\"https:\/\/synopower.club\/it\/\" target=\"_blank\" rel=\"noreferrer noopener\">SynoPower Club<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>NAS security is usually described as a list of switches inside DSM. For a NAS that only holds family photos, that list is enough. Ours does something riskier: SynoPower Club, a store that takes payments in 16 languages, is served from a Synology NAS in our own rack, so every scanner and botnet on the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":21907,"comment_status":"open","ping_status":"closed","template":"","meta":{"_eb_attr":"","footnotes":""},"doc_category":[197],"doc_tag":[],"class_list":["post-21908","docs","type-docs","status-publish","has-post-thumbnail","hentry","doc_category-nas-hosting-101"],"blocksy_meta":{"styles_descriptor":{"styles":{"desktop":"","tablet":"","mobile":""},"google_fonts":[],"version":8}},"year_month":"2026-10","word_count":2978,"total_views":"1","reactions":{"happy":"0","normal":"0","sad":"0"},"author_info":{"name":"Adair Hsu","author_nicename":"adairpk17","author_url":"https:\/\/synopower.club\/it\/author\/adairpk17\/"},"doc_category_info":[{"term_name":"NAS Hosting 101","term_url":"https:\/\/synopower.club\/it\/docs-category\/nas-hosting-101\/"}],"doc_tag_info":[],"_links":{"self":[{"href":"https:\/\/synopower.club\/it\/wp-json\/wp\/v2\/docs\/21908","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/synopower.club\/it\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/synopower.club\/it\/wp-json\/wp\/v2\/types\/docs"}],"author":[{"embeddable":true,"href":"https:\/\/synopower.club\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/synopower.club\/it\/wp-json\/wp\/v2\/comments?post=21908"}],"version-history":[{"count":1,"href":"https:\/\/synopower.club\/it\/wp-json\/wp\/v2\/docs\/21908\/revisions"}],"predecessor-version":[{"id":21910,"href":"https:\/\/synopower.club\/it\/wp-json\/wp\/v2\/docs\/21908\/revisions\/21910"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/synopower.club\/it\/wp-json\/wp\/v2\/media\/21907"}],"wp:attachment":[{"href":"https:\/\/synopower.club\/it\/wp-json\/wp\/v2\/media?parent=21908"}],"wp:term":[{"taxonomy":"doc_category","embeddable":true,"href":"https:\/\/synopower.club\/it\/wp-json\/wp\/v2\/doc_category?post=21908"},{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/synopower.club\/it\/wp-json\/wp\/v2\/doc_tag?post=21908"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}