RT6600ax Safe access and NAS alert ?

Currently reading
RT6600ax Safe access and NAS alert ?

14
0
Router
  1. RT6600ax
Operating system
  1. Linux
  2. Windows
Mobile operating system
  1. Android
Last edited:
Hello,
I have a nas qnap behind my 6600AX. Safe access is activated and I notice that it blocks about 100 ip per day for "security reasons". The threat intelligence database box is enabled but my nas seems to be targeted.

This is not understandable because on my nas the accesses are only internal (lan ip) and I don't notice anything on it.
How can this be done? I don't have any redirected ports on the 6600AX. The nas should not even be detected from outside?
Nothing is running on my nas, it is only a file server with jellyfin. Or on the other hand, is it my nas that tries to make strange accesses?

Thanks
 

Attachments

  • Capture d’écran 2023-01-22 194957.png
    Capture d’écran 2023-01-22 194957.png
    108.9 KB · Views: 27
I've put some ip of the list in my NAS firewall in the rejected list, but I still have the detections on the synology. Very strange
 
Hi, its weird.
I've Block in srm firewall the traffic from the nas toward internet, but ive got the same errors again in safe access. Perhaps it is inbound traffic searching my nas ?
 
Hi, its weird.
I've Block in srm firewall the traffic from the nas toward internet, but ive got the same errors again in safe access. Perhaps it is inbound traffic searching my nas ?
Tbh it is hard for me to translate the image above... maybe you are indeed having internal (LAN) traffic being captured in this case
 
Safe Access is an outbound access control mechanism, meaning that it controls requests coming from your LAN/WLAN devices. From the screen shot you have requests originating from your NAS, MaiyonNAS, towards the logged, and blocked, IP addresses. So you should investigate what these IP addresses could be hosting and it may be that you are ok with this access, so create a new profile that allows it and add the NAS to it's list of devices.

I can't remember if Safe Access acts before or after SRM firewall, but it sounds from your results that SA is before and so you still get the logged events. For Threat Prevention this happens after the SRM firewall and so a FW deny rule will stop TP from intercepting those sessions.

So what are these IP addresses that the NAS is trying to access? Could be, just a few ideas and there will be others you can probably think of:
  • QNAP servers, e.g. software update.
  • QNAP package/application requesting content, e.g. mail server caching attachments or HTML linked content, or a downloader/torrent service.
  • Docker container/VM getting whatever it wants, or contacting whoever it wants.

I just checked the first four IP addresses at AbuseIPDB - IP address abuse reports - Making the Internet safer, one IP at a time: three are in China and the other is South Korea. But all four had a list of reports, mostly for ingress activity but I guess if they are questionable then you can ask "should my devices be trying to access them?".
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Similar threads

From memory of setting up Safe Access: Safe Access intercepts DNS requests sent to the router and it...
Replies
2
Views
5,235
On a Windows 10 Enterprise in Edge browser when I try to enter Safe Access it says the same, just more...
Replies
4
Views
1,522
  • Question
User defined Destination NAT (DNAT) /Source NAT (SNAT) is what is needed. My last router had this and...
Replies
1
Views
1,975
  • Question
Fredbert, thanks a lot! Your primary/secondary DNS configuration did the trick! Works!
Replies
7
Views
2,180
I've already posted this in Synology official forum, but maybe here I get more help, or quicker :-) I'm...
Replies
0
Views
1,083
Interesting. It’s likely this is just a one off. It seems the wired devices I could see before the upgrade...
Replies
2
Views
1,998
When you are considering about bridge mode in the exist Asus router then 2200 as primary managed router =...
Replies
5
Views
3,339

Welcome to SynoForum.com!

SynoForum.com is an unofficial Synology forum for NAS owners and enthusiasts.

Registration is free, easy and fast!

Trending threads

Back
Top