Cant change my server connection from my IP to synology.me

Currently reading
Cant change my server connection from my IP to synology.me

119
9
NAS
DS918+
Operating system
  1. Windows
Mobile operating system
  1. Android
I have an error SSL certificate has been changed and it says the SSL certificate does not belong to the IP address and sign in with synology.me. I tried that and it wont let me switch it.
 
So on the desktop app of active backup for business, I want to change my connection from the IP to blank.synology.me
 
From memory:

ABB client will silently fail to connect and update when using the NAS IP as the server name when the SSL certificate assigned to ABB has been renewed/changed. You can right-click the ABB client icon and select Edit Connection then save it again: this forces the client to revalidate the connection and notify you that there's a SSL certificate mis-match.​

When using the NAS IP or any other domain name that isn't explicitly covered by the SSL certificate you will have a second step when setting up the client's connection: it will tell you the connection isn't trusted but do you want to proceed. You tell it do proceed but next time the certificate changes the client doesn't alert you but instead just stops connecting. This is not that great!

Now you have changed to using server name mynas.synology.me, because you know you have a SSL certificate assigned to ABB that covers this name, you will also have to confirm that the routing between PC client and NAS is working.

The PC client connects to the the NAS using TCP 5510 for ABB server. This would be a direct connection when using the NAS IP but with mynas.synology.me then this domain name is being resolved to the Internet IP of your router. So unless the router support NAT loopback then the connection will fail as the router won't be listening on port 5510. Firstly, you will have to add a port forward rule in the router to send TCP 5510 to the NAS LAN IP and then hope the router supports NAT loopback. If this now fails you will know it isn't supported.

The alternative to adding a port forward rule in the router would be to edit the PC's host file and assign mynas.synology.me to NAS LAN IP. Not something I have done on PC as I only dig in the macOS / Linux garden. But this will probably be the simpler way if you don't plan to use ABB client -> server when away from the LAN. It also should work when away but connect back through a VPN tunnel.
 
Well that does sound complicated. Ill give it a try. Thanks for the info. How do you know when the certificate will expire?
 
How do you know when the certificate will expire?
Control Panel -> Security -> Certificate

Each certificate shows its expiry date after the certificate name. If it's a Let's Encrypt certificate then they expire after 3 months but should auto-renew. Even auto-renewed LE certs will cause the ABB client to stop connecting ... unless they cover the server name you use in the ABB client.
 
Also, note that there are two parts to the ABB service:
  1. ABB server that is listening on port 5510 for PC backups.
  2. ABB restore web portal, which is listening/accessible by HTTP/HTTPS using whatever application portal servername / port numbers you've assigned.
Both these require a SSL certificate to match the server name that you use to access each, but they don't have to be the same. But the ABB client will assume the server name is the same for both service elements.
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Similar threads

To change the username/password I think you have to Log Out first, but this requires a DSM admin user to...
Replies
2
Views
372
  • Question
^ this is the way. OP it's a 2 drive NAS - keep it simple unless there's a valid technical reason for...
Replies
3
Views
1,278
Deleted member 5784
D
Hi, when trying to connect a new hypervisor I get this message. However, I do not have such a hypervisor...
Replies
0
Views
1,158
  • Question
Been using it on both Intel and ARM Macs since day 1 and haven't had a situation like yours. Does the menu...
Replies
9
Views
3,402
I have multi site replicated shares using DFSR back to a central file server that is backed up with ABB...
Replies
0
Views
1,150
  • Question
@pbrennan845 You can change the task by first changing the display role on the left side, choose the...
Replies
1
Views
3,293
Hi, I am backing up a server to a remote Synology. Synology connects to it via the hostname of my WAN...
Replies
0
Views
1,524

Welcome to SynoForum.com!

SynoForum.com is an unofficial Synology forum for NAS owners and enthusiasts.

Registration is free, easy and fast!

Back
Top