you are on the new server domainname will switch later
If you can not login please clear cookies
chevron_left
chevron_right
The-Photo forum
  • Home
  • Forums
    • theatersImage Discussions arrow_forward
      • chat_bubbleChallenges arrow_forward
        • camera Edit me an Image
        • camera Photo of the Week
      • chat_bubbleHave your photos Critiqued arrow_forward
        • camera Wednesday C&C
      • Showcase your Photos
      • chat_bubbleWeekly & Topic Image Threads arrow_forward
        • camera Abstract/Experimental
        • camera B&W Threads
        • camera Sunday Cats!
        • camera Weekly Collegial forum
        • camera Daily Outing
        • camera This week through your eyes
        • camera Landscape
        • camera Street Photography
    • theatersMiscellaneous forums arrow_forward
      • Photo Hardware Discussions
      • Industry News
    • theatersOther Photography Talk arrow_forward
      • General Articles
      • Photo History Trivia
      • Open discussions
      • Technical Discussions
    • theatersSite Discussions arrow_forward
      • Governance and organisation
      • Updates & Bugs
    • theatersWelcome arrow_forward
      • chat_bubbleForum Guidelines arrow_forward
        • camera Misplaced Posts
      • Introduce yourself
  • Threads
  • Users
  • Web Site
  • message
  • group
  • chevron_right Threads
  • label Other Other Photography Talk
  • label TQ Technical Discussions

Synology DiskStation

MarshallG
April 24, 2023
chat_bubble_outline 116
arrow_downward first_page chevron_left chevron_right last_page
  • link
    JimKasson
    Members 1738 posts
    April 26, 2023, 3:35 p.m. April 26, 2023, 3:35 p.m.
    link
    @Flashlight has written:

    You do not handle the security, Synology does that.

    You have to open firewall ports to the Synology box, unless you run wide open, which I don't think is a good idea. Unless you have a DMZ, you have outside traffic on your internal network. Synology can't fix that.

  • link
    JimKasson
    Members 1738 posts
    April 26, 2023, 3:37 p.m. April 26, 2023, 3:37 p.m.
    link
    @Flashlight has written:

    take it you trust Google more than Synology; my view is the opposite. Sending all your personal stuff to Google is, as we say in the Netherlands, 'tying the cat to the bacon', IOW you're sure the bacon gets eaten by the cat. Synology has a different business model. The bacon is only eaten if a hacker penetrates the Synology system.

    You are right. I am more worried about local web servers and local networks being compromised than I am about either Google Workspace being compromised or somebody at Google taking my images.

  • link
    Flashlight
    Members 137 posts
    April 26, 2023, 3:44 p.m. April 26, 2023, 3:44 p.m.
    link
    @JimKasson has written:
    @Flashlight has written:

    You do not handle the security, Synology does that.

    You have to open firewall ports to the Synology box, unless you run wide open, which I don't think is a good idea. Unless you have a DMZ, you have outside traffic on your internal network. Synology can't fix that.

    It doesn't work that way. All you have to do is join the free 'connect.to' service of Synology and they provide some sort of tunnel from their servers to the DiskStation through the CloudStation app. I do not know how it works exactly, although I wondered. If you cut the power to your DiskStation you get an email stating 'connection to ... was lost at ... time'.

    I used to have a DMZ with a small Synology running a website where clients could order images while the large original files and database were on a large Synology on the local network. So I do know what you talk about, but this CloudStation scenario works differently.

  • link
    Flashlight
    Members 137 posts
    April 26, 2023, 3:46 p.m. April 26, 2023, 3:46 p.m.
    link

    Guess it's a VPN (Virtual Private Network)

  • link
    JimKasson
    Members 1738 posts
    April 26, 2023, 3:54 p.m. April 26, 2023, 3:54 p.m.
    link
    @Flashlight has written:

    It doesn't work that way. All you have to do is join the free 'connect.to' service of Synology and they provide some sort of tunnel from their servers to the DiskStation through the CloudStation app. I do not know how it works exactly, although I wondered. If you cut the power to your DiskStation you get an email stating 'connection to ... was lost at ... time'.

    How does the Synology box get to the internet if not through the firewall?

  • link
    Flashlight
    Members 137 posts
    April 26, 2023, 3:56 p.m. April 26, 2023, 3:56 p.m.
    link
    @JimKasson has written:
    @Flashlight has written:

    It doesn't work that way. All you have to do is join the free 'connect.to' service of Synology and they provide some sort of tunnel from their servers to the DiskStation through the CloudStation app. I do not know how it works exactly, although I wondered. If you cut the power to your DiskStation you get an email stating 'connection to ... was lost at ... time'.

    How does the Synology box get to the internet if not through the firewall?

    Are you saying VPN solutions are unsafe by design?

  • link
    AlanSh
    Forum Admin 3299 posts
    April 26, 2023, 4 p.m. April 26, 2023, 4 p.m.
    link
    @JimKasson has written:

    How does the Synology box get to the internet if not through the firewall?

    The server creates an outbound private connection to Synology. Same principle as your email client. There's no firewall ports need opening.

    Alan

  • link
    JimKasson
    Members 1738 posts
    April 26, 2023, 4:07 p.m. April 26, 2023, 4:07 p.m.
    link
    @Flashlight has written:

    Are you saying VPN solutions are unsafe by design?

    Not by design. I don't know of anyone who has set out to design an unsafe VPN. VPN quality is variable, and hard for IT people to understand, especially if not widely implemented with many customers. I wouldn't necessarily trust Synology's implementation. Do you know where their technology came from?

    If people can access the Synology-served photos from a web browser, it needs more than a VPN connection to the internet. If they are doing their own hosting for the web users, then the VPN connection is sufficient.

  • link
    JimKasson
    Members 1738 posts
    April 26, 2023, 4:08 p.m. April 26, 2023, 4:08 p.m.
    link
    @AlanSh has written:

    The server creates an outbound private connection to Synology. Same principle as your email client. There's no firewall ports need opening.

    What ports does the server use for the outbound private connection?

  • link
    Flashlight
    Members 137 posts
    April 26, 2023, 4:09 p.m. April 26, 2023, 4:09 p.m.
    link
    @AlanSh has written:
    @JimKasson has written:

    How does the Synology box get to the internet if not through the firewall?

    The server creates an outbound private connection to Synology. Same principle as your email client. There's no firewall ports need opening.

    Alan

    And I guess that as long as the Synology and other computers are on the local network the files never touch the Internet but are exchanged between the CloudStation apps on the Synology and the computers. As you also have to install a CloudStation app on each computer that want to participate.

    AlanSh likes this.

    favorite 1

  • link
    Flashlight
    Members 137 posts
    April 26, 2023, 4:10 p.m. April 26, 2023, 4:10 p.m.
    link
    @JimKasson has written:
    @Flashlight has written:

    Are you saying VPN solutions are unsafe by design?

    Not by design. I don't know of anyone who has set out to design an unsafe VPN. VPN quality is variable, and hard for IT people to understand, especially if not widely implemented with many customers. I wouldn't necessarily trust Synology's implementation. Do you know where their technology came from?

    If people can access the Synology-served photos from a web browser, it needs more than a VPN connection to the internet. If they are doing their own hosting for the web users, then the VPN connection is sufficient.

    To see the photos you need to open the standard http: or https: ports. It's a web service and not a part of the CloudStation app.

  • link
    JimKasson
    Members 1738 posts
    April 26, 2023, 4:10 p.m. April 26, 2023, 4:10 p.m.
    link
    @AlanSh has written:

    The server creates an outbound private connection to Synology. Same principle as your email client. There's no firewall ports need opening.

    I have to open up ports for my email clients. There are a lot of ports that email clients can use.

  • link
    Flashlight
    Members 137 posts
    April 26, 2023, 4:15 p.m. April 26, 2023, 4:15 p.m.
    link
    @JimKasson has written:
    @AlanSh has written:

    The server creates an outbound private connection to Synology. Same principle as your email client. There's no firewall ports need opening.

    What ports does the server use for the outbound private connection?

    6690
    kb.synology.com/en-global/DSM/tutorial/What_network_ports_are_used_by_Synology_services

  • link
    acskinner
    Members 17 posts
    April 26, 2023, 4:19 p.m. April 26, 2023, 4:19 p.m.
    link

    I've been meaning to watch this:

    www.youtube.com/watch?v=VOL-GLi8Qqw

    About Synology and photos. I've watched some of this blokes stuff and he seems largely sensible. To me at least. He pins a lot of BTRFS snapshots.

  • link
    JimKasson
    Members 1738 posts
    April 26, 2023, 4:19 p.m. April 26, 2023, 4:19 p.m.
    link
    @Flashlight has written:
    @JimKasson has written:

    What ports does the server use for the outbound private connection?

    6690
    kb.synology.com/en-global/DSM/tutorial/What_network_ports_are_used_by_Synology_services

    Thanks. That is a lot of ports if you look at all the services. UDP ports make me nervous. Do you just open 6690 to just the Synology box?

  • link
    JimKasson
    Members 1738 posts
    April 26, 2023, 4:23 p.m. April 26, 2023, 4:23 p.m.
    link
    @Flashlight has written:

    To see the photos you need to open the standard http: or https: ports. It's a web service and not a part of the CloudStation app.

    So the Synology box acts as a web server, and needs to be isolated like a web server, right?

  • link
    Flashlight
    Members 137 posts
    April 26, 2023, 4:27 p.m. April 26, 2023, 4:27 p.m.
    link
    @JimKasson has written:
    @Flashlight has written:
    @JimKasson has written:

    What ports does the server use for the outbound private connection?

    6690
    kb.synology.com/en-global/DSM/tutorial/What_network_ports_are_used_by_Synology_services

    Thanks. That is a lot of ports if you look at all the services. UDP ports make me nervous. Do you just open 6690 to just the Synology box?

    Cloud Station - 6690 - TCP

    What are you trying to prove Jim?

  • link
    JimKasson
    Members 1738 posts
    April 26, 2023, 4:31 p.m. April 26, 2023, 4:31 p.m.
    link
    @Flashlight has written:
    @JimKasson has written:
    @Flashlight has written:
    @JimKasson has written:

    What ports does the server use for the outbound private connection?

    6690
    kb.synology.com/en-global/DSM/tutorial/What_network_ports_are_used_by_Synology_services

    Thanks. That is a lot of ports if you look at all the services. UDP ports make me nervous. Do you just open 6690 to just the Synology box?

    Cloud Station - 6690 - TCP

    What are you trying to prove Jim?

    Nothing. I thought people were saying that Synology did all the security, and the user didn't have to worry about it. I don't see how that's possible. The user needs to open the ports the Synology needs open, and figure out a way to not have those ports open to other boxes than the Synology boxes. That sounds like the user needs to be responsible for the security of the network.

arrow_upward first_page chevron_left chevron_right last_page

There are 45 more posts in this thread.

  • DPRevived.com & the-photo.org are owned and operated by The Photographer's Foundation Limited, registered in England, company number 14795583. Contact us here https://the-photo.org/contact.html
powered by misago