Safe Access SRM 1.3 new options for Safe Access

Currently reading
Safe Access SRM 1.3 new options for Safe Access

fredbert

Moderator
NAS Support
Subscriber
5,153
2,085
NAS
DS1520+, DS218+, DS215j
Router
  1. RT2600ac
  2. MR2200ac
  3. RT6600ax
  4. WRX560
Operating system
  1. macOS
Mobile operating system
  1. iOS
Having just upgraded SRM to 1.3.1 I was looking at what's changed and notice two new settings that address DNS over HTTPS and Apple's iCloud Relay. Both these interfere with Safe Access's ability to apply web filtering.

First, Apple's iCloud Relay gets a Block setting in each Profile within Safe Access...

1662312063238.png

Prior to this (in SRM 1.2.5) you had to have an internal DNS server that resolved (to nowhere specific) for two addresses: mask.icloud.com; mask-h2.icloud.com. Such as like this:

1662312211587.png

So DNS Server no longer needs master zones for these two addresses, if you wanted to stop using iCloud Relay at home.


Next it's DNS over HTTPS (DOH). SRM has for some time supported using DOH for DNS resolution from clients requesting it from the router. But there was little to stop clients just using DOH directly and so bypassing Safe Access.

In Network Center's Security configuration there is a new option 'Do not allow client devices to use DOH servers'.

1662312603342.png

1662312495231.png
Give them a go and see if they work for you.
 
Last edited:
I'd like to thank myself for posting the above because I couldn't remember, nor find in Help, where the iCloud Relay setting had been added.

Since iOS 16, well it's been noticeable since upgrading my iPhone, I've been having a lot of iOS notifications saying that iCloud Private Relay isn't working. Er, I know! This happened even when picking up the phone at home when the network shouldn't have changed.

I had enable the new Safe Access feature on my profiles and also disabled the DNS Server zones that had previously been blocking access (as per Apple's guidance). So now I've re-enabled the two DNS Server zones and the notifications seem to have stopped. I would guess that the Safe Access feature is not responding correctly to how iOS expects for a correct block, and so it is giving more a service status notification. Whatever, it's rather annoying.

Here's how to implement Apple's recommended block using DNS Server.
 
I'm wondering if the best way to stop the notifications on your home wireless LAN will be to go the iOS Settings /Wi-Fi and select your home network. Now ensure that Limit IP Address Tracking is disabled. I find a Wi-Fi off/on toggle helps sometimes too. This and use the iCloud Private Relay blocking techniques.
 
Hello. Just to clarify, if a user has Private Relay enabled on their Apple device then the traffic bypasses SA? On the contrary if PR is disabled on the device then SA will filter the traffic and apply the rules.
 
In short: yes.

With Safe Access in SRM 1.3 there is the option, in each profile, to block access to iCloud Private Relay. Before this in SRM 1.2 you had to set local DNS resolution to give false IP addresses for a couple of Apple URLs.

This is the same scenario where a device uses any Internet VPN service to tunnel through the local and ISP infrastructure, thereby breaking out onto the Internet from the VPN service's gateway.

Since updating to iOS 16 I have had more iOS notifications from private relay saying it's on/off while I'm always on the same home SSID. I've discussed this with Synology Support and the feedback is that they are doing the same mechanism in SRM 1.3 Safe Access that Apple is recommending to do in DNS. I'm feeling that it's either an SRM 1.3 WiFi stability issue or more likely something in iOS 16 flapping the wireless and mobile connections. I don't have the same issue with an WiFi-only iPad on 15.7.
 
Ok. I will have to explore this a little more with my own devices some on 15.7 and others on 16. Thanks for the help and post updates.
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Similar threads

Thanks for replying, I like the idea I can backup my RT2600 and then upload that to the 6600…at least in...
Replies
40
Views
6,554
I must have struck a nerve! 🤩
Replies
59
Views
4,415
I tend to use pihole and unbound, pihole is very good for getting rid of ads, and you can run it in a...
Replies
4
Views
1,160
I have a running ticket with Synology support and I have been troubleshooting this issue where a device...
Replies
13
Views
2,894
Release Notes for Safe Access Description: Safe Access integrates advanced parental control and...
Replies
0
Views
2,096
Some very quick testing... My normal SRM firewall rules include specific outbound rules to permit LAN...
Replies
6
Views
4,060

Welcome to SynoForum.com!

SynoForum.com is an unofficial Synology forum for NAS owners and enthusiasts.

Registration is free, easy and fast!

Trending threads

Back
Top