Firewall rules to prevent hacking attempts

Currently reading
Firewall rules to prevent hacking attempts

3
1
NAS
DS218+
Operating system
  1. Windows
Mobile operating system
  1. iOS
Hi All,
I've got a ds218+ setup running Plex/Sab/Sonarr/Radarr in Docker, in the last week I've had someone trying to access DSM using the default admin account. This will not work as the admin account is disabled, however it's annoying as I can see them trying this pretty frequently so I'm looking at ways to block them.

I've changed the default port for DSM, which appears to have made no difference.

I've tried setting up Firewall rules based on a few guides I've seen, however when I enable the firewall rules I've created, it blocks Sab/Sonarr/Radarr as well, clearly I'm doing something wrong but I'm not 100% sure what at this point, so any help would be Greatly appreciated!

I've got the below setup as custom firewall rules as things stand and the "LAN" section under interfaces drop down has the deny access radio button ticked.

Apologies if this has already been covered, I did search and try a few things that have been suggested elsewhere but nothing I've tried so far has made any difference.
1662461617770.png
 
Turns out it was a firewall rule to allow the docker network subnet that was missing, so the NAS was unable to resolve DNS. Added the subnet from the Docker network config and it works like a charm - hacking tosser blocked, Docker containers working.
 
Not sure how those other docker rules help. Did you test them?
I have now yea, seems like it was the docker network element that was the issue and these don't offer anything so I've disabled them.

Probably more my lack of understanding on how these things work, Haven't done much work with firewalls before so still learning.
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Similar threads

Hello! Yes I did indeed find the problem, there are some special firewall rules that you need to make for...
Replies
4
Views
922
  • Question
Generically you would. 1. Allow specific IPs/Ports from your local LAN 2. Allow specific IP/Port for VPN...
Replies
5
Views
5,390
Morning lads I'm having some issues with with an IP camera I recently bought (Reolink e1 pro), I've...
Replies
0
Views
1,446
DSM 7 I know, that is the solution I actually ended up with. But it does not actually do what I wanted...
Replies
6
Views
1,933
Hello, I am trying to utilize the firewall on my ds918+ to limit access to ports on my synology to...
Replies
0
Views
3,275
OK. I have 1.json but the other is 1590505357.json, go figure :) Hence why I couldn't say how they got...
Replies
12
Views
5,043
Thanks very much everyone. Over the VPN, the session shows that the source is from 10.4.0.1, the VPN...
Replies
14
Views
5,575

Welcome to SynoForum.com!

SynoForum.com is an unofficial Synology forum for NAS owners and enthusiasts.

Registration is free, easy and fast!

Trending threads

Back
Top