Reverse proxy setup for intranet

Currently reading
Reverse proxy setup for intranet

6
0
NAS
DS920+
Router
  1. RT6600ax
Operating system
  1. macOS
Mobile operating system
  1. iOS
Hi,

I have Synology Router and NAS setup on the same VLAN. I am self-hosting bunch of containers (around 16) on NAS and would like to setup reverse-proxy so that I can access intranet website without the http://local-id:port.

I have purchased a gTLD on Cloudfare and tried to follow the steps mentioned here

However, I am stuck at setting up webroot and the next steps seem vague for my skill level. I can build/run docker containers but my knowledge in networking concepts is not great. Can any kind soul translate these instructions so that I can set up the reverse proxy :)

I have found another blog that tries to setup reverse-proxy (with internet access which I am not looking for) using Traefik. The guide is available here

PS: If you have any other material that I can follow through, that will be helpful as well

Thanks
 
Right now, I use NAS_IP:Container_Port and it works. I am looking to setup reverse-proxy to make it easy to type in the address rather than having to remember the port. It is more of a convenience :)
 
Right now, I use NAS_IP:Container_Port and it works. I am looking to setup reverse-proxy to make it easy to type in the address rather than having to remember the port. It is more of a convenience :)
Why not then setup a local DNS server and zone for your "internal" domain name and be done with it? Set up upstream servers for any requests going towards the internet, and all the local hosts for all your internal containers, no reverse needed.

The official KB article on DNS can explain how to do it, and there are already several DNS threads on the forum explaining this. Most are from @fredbert.
 
Last edited:
Hi. I will definitely look into this. Can this work with DoH setup like Adguard or NextDNS. I have currently enabled DoH on the Synology router.

Thanks @fredbert for your article. I am reading through it and will try to setup following your instructions. Once again, thanks for the sharing your knowledge and pointing me an easy solution
 
Not quite sure what you mean about working with DOH. There is Safe Access and in SRM 1.3 there is somewhere a setting to stop LAN requests to DOH servers, while SRM itself can use DOH servers. Have a look at SRM’s built in help.

I don’t want LAN devices to use DOH and bypass Safe Access, so this works well for me.
 
I am inclined to use Dns-Over-Https (DOH) to block ads on my devices. I looked into the tutorial and it seems like I have have to type in the port number while setting it up? Is that correct ?
 
Not sure how DOH in and of itself stops adverts, it’s a transport to a server that’s still doing resolution for the requests it receives. It’s the decision process that the server employs by way of filters and intelligence that could result in some requests not resolving to the actual destination: this can be used to apply control to accessing certain destinations, such as categorisation of some destinations being undesirable, or thought to be compromised or malicious.

DOH uses HTTPS to hide the requests from being readable by the network infrastructure that lies between the client and DNS server. It used to be easy to force users to use approved DNS servers (usually done in business environments) by implementing firewall rules that restricted access to TCP and UDP ports 53. By using DOH this is harder as the client is using the HTTPS port 443, this then allows users to bypass access controls that block access to undesirable content but more importantly protect form accessing malicious content.
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Similar threads

  • Question
I have two networks: 1. Primary (not isolated) 2. IOT (not isolated) NOTE: There are currently no...
Replies
0
Views
2,224
That's what I have setup at home for about 50 devices (but with an RT2600). I have a 2 x Unifi AP's...
Replies
6
Views
1,722
I see. Thanks. I'll evaluate my potential need for WRX560'a once I've lived with RT660ax + MR2200ac's for...
Replies
6
Views
3,096
@akahan , I have confirmed I get a properly (HTTPS)-secured page load when I access SRM via the DDNS...
Replies
14
Views
4,348

Welcome to SynoForum.com!

SynoForum.com is an unofficial Synology forum for NAS owners and enthusiasts.

Registration is free, easy and fast!

Trending threads

Back
Top