Question When your IP block list has single or more entry

Currently reading
Question When your IP block list has single or more entry

jeyare

Giga Poster
NAS
1811+, 3x 1813+, ... Ubiquiti Unifi networks
Check your Control panel/Security/Account .... Allow/Block list
when you have single or more IPs here in past 30 days something is wrong in your setup of:
- router firewall
- opened ports in router
- router IPS (if any)
- DSM Auto block configuration (Auto block must be enabled, max. 2 Login attempts, max. size of minutes within)
- you or your users frequently forgetting your usr/psw

Then it's a time to check it, because dark power is watching you.
 

Shadow

Kilo Poster
NAS
DS216+II, DS118
Router
RT2600ac, MR2200ac
I haven't had a single unknown login attempt (from the Internet) ever since I closed ports 5000/5001 on my routers some time ago.
 

WST16

Giga Poster
NAS
DS216+II : DS118 : APC Back UPS ES 700 — Mac/iOS user
I have account blocks registered almost daily –after one wrong attempt to access mail as I set it– because port 25 is open. Sometimes even over 10 attempts/day.
 

jeyare

Giga Poster
NAS
1811+, 3x 1813+, ... Ubiquiti Unifi networks
I have lot of public services running in my NAS farm. Also I have public fixed addresses. Till May it was 20-50/ daily blocked IPs by my NAS.
But from May when I was changed the network topology I have zero attempts from external IPs to be written in my NAS Block list.
 

WST16

Giga Poster
NAS
DS216+II : DS118 : APC Back UPS ES 700 — Mac/iOS user
I haven't had a single unknown login attempt (from the Internet) ever since I closed ports 5000/5001 on my routers some time ago.
Aren’t you running Mail Server?
 

fredbert

Giga Poster
I generally have SRM's Threat Prevention blocking scans and various perceived threats. Sometimes I add a specific SRM FW deny rule for the class B subnet and monitor it for a while and later add just that IP to the block list if they come back again.

On DSM I don't get any automatic blocked IPs. I changed the default ports and don't allow SSH login from the Internet. For inbound Mail Server I've an SRM FW rule to permit forwarded mail from my email service and a second rule to block from everywhere else (in case the NAT rule enables forwarding from anywhere).

I use DSM FW but mostly SRM's since migrating from Apple Airport's 'everyone or no-one' approach to port forwarding.
 

WST16

Giga Poster
NAS
DS216+II : DS118 : APC Back UPS ES 700 — Mac/iOS user
Often times it’s like a drive–by shooting for me. Very intense and then it stops.
When a few days go by without a push notification of a block, I go check the Mail service to make sure it’s running :D
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Welcome to SynoForum.com!

SynoForum.com is an unofficial Synology forum for NAS owners and enthusiasts.

Registration is free, easy and fast!

Top