Install the app
How to install the app on iOS

Follow along with the video below to see how to install our site as a web app on your home screen.

Note: This feature may not be available in some browsers.

Snapshot Replication Retention Strategy...Ransomware Etc. Advanced Retention Policy?

As an Amazon Associate, we may earn commissions from qualifying purchases. Learn more...

14
2
NAS
DS1821+, DS1815+, DS418j
Router
  1. MR2200ac
  2. RT6600ax
Operating system
  1. macOS
  2. Windows
Mobile operating system
  1. iOS
Last edited:
Hi,

So I'm trying to figure out the best way to set something up. I have Nas1 that replicates over to Nas2 (backup). Nas2 isn't connected to the internet, (firewall, access control, app privileges etc.), basically it can only be accessed by one local computer and Nas1). Separate accounts/pass 2fa etc., I have DSM/everything else locked out of the port/account that Nas1 uses to connect, and I physically pull the other (admin) lan cable. But, one issue is Nas2 is older (DS1815), so no immutable snapshots.

So one potential I was thinking of is, if someone got into Nas1 they could just keep pushing snapshots over to Nas2 until they overwrite all the old ones. Even if I turn retention policy off, they could just do more than 1024; is that right? So I was thinking some kind of advanced retention, but I don't really understand the rules TBH.

Does this look right? Thanks for any help!


Screenshot 2024-05-23 at 20.30.13.webp
 
Actually I could be wrong, leaving retention policy off might be the safest:

Always retain snapshotsThe maximum number of shared folder snapshots is 1,024, and 256 for LUN snapshots. When the number of snapshots reaches the limit, the system cannot take any new snapshots.

So worst they can do is fill it up.
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Similar threads

  • Question Question
I do not see this example on any user account on any device running SR. Maybe this was an older SR task...
Replies
3
Views
1,224

Thread Tags

Welcome to SynoForum.com!

SynoForum.com is an unofficial Synology forum for NAS owners and enthusiasts.

Registration is free, easy and fast!

Trending content in this forum

Back
Top