External Access to Synology (Port Forwarding/Dynamic DNS)

Does this occur for both AFP and SMB?

Check out Tailscale. I have it installed on all my machines. Makes it easy to access when not at home.

3 Likes

UPDATES:

WORKING
ā€¢ Able to now access admin page via ddns host (yea!) remotely. :slightly_smiling_face:
ā€¢ WebDav now workingā€¦still rough around the edges :smile:

STILL NOT WORKING

  • SMB/AFP remote connections, mounting drive when remote.
    (requests for access, then message printed above not compatible.)
    @JKoopmans - both

NEW DISCOVERY
Appears Appleā€™s office apps (Numbers, Pages, Keynote etc.) no longer work w/WebDav protocolā€¦ so finally get through this challenge to learn Apple removed WebDav. Rabbit holes for apps that fill the gap.

Looking to work on single office file hosted on synology, not creating copies of said files. Even the Move option inside the office apps turns into a ā€˜copy toā€™ so you are not working from a single folder.

@bolero when vpn encrypted, how is the traffic anonymized?

Thought Tailscale was a basic VPN and now seeing it is more about network setups. I miss the days of Hamachiā€¦and while Hamachi is still sort of around it seems faded and a fraction of what it once did.

okā€¦checking this out. not seeing a synology option? there appears to be a linux versionā€¦no synology?

I use this

1 Like

@pixr

Just joined these forums. I am a SysAdmin (jack-of-all-computer-trades actually) with Macs and Synology NASs among my home lab. Either reply to this reply or DM me. We can move to Slack/Discord if it will help troubleshoot in real time. (No charge, just glad to help).

2 Likes

Himachi is really not viable for what you want. You also got a Synology to be self-sufficient and using Himachi ties you firmly with yet another corporate entity between you and your Synology. You just need the OpenVPN that ships with Synology.

This would be great, see DM.
Made some decent progress over the weekend as well.

@pixr @Tinjaw - How are you folks making out?
Sure Iā€™m not alone in wanting to hear the resolution.

Thinking I am about 75% through this phaseā€¦here are the updates.
~ phase 1 = file management
~ phase 2 = file backup w/time capsule (do not expect this one to be as challenging)
~ phase 3 = media center

  • FQDN working w/host name and ip. QuickConnect disabled and needed services are working.

  • A number of ports are currently opened and trying to get TailScale working effectively (and then close all ports.) This has been a problem. TailScale is installed and activated on Synology and iPhone; TailScale dashboard shows both devices as active and available. That said, canā€™t do anything further. Anyone up for pitching in to get TailScale working right?

  • Disappointed to get this far to discover that every workflow option to date requires extra time and taps. The routine of selecting specific photos from the photo album, moving them to a network directory (soon to by synology) and then deleting those same photos is a monotonous and something I am doing so many times a day. The synology solution is the way to go, and yet that same process now requires extra taps and comes w/a additional delay. No matter what option or 3rd party app I am not yet finding a solution. Some of the apps have shortcuts, but those shortcuts themselves are yet another directory way (adding yet another tap) AND none of the favorite shortcuts appear to be accessible from the iOS share sheet.
    I have been using Resilio Sync as a workaround for the last year or two and it has been working great (for what it does, but not the final solution) and this workflow is hands down faster than the others.

No response from Tinjaw
~ and while you ask in jest, that is the update all the same.

Certainly admire your fortitude, and while I know I am not the
sharpest knife in the drawer, still continue to be confused as
to your goal.

In this (and other posts) you indicate you are pursuing Tailscale
which is ā€œdistributed WireGuardā€ , so I donā€™t see how
that relates to your desire for anonymization? Which I understood
to be the reticence for a VPN.

WRT photos - Have you used the Synology iOS app? Which I
agree that none of their apps (on any platform) are world class,
you can just hit the button, and have them all ingested. That is
what I do, and then use Photos, whatever, to process.

2 Likes

Hello CSF111,

Goal - short answer = home-rolled iCloud (only for file management)
Goal - medium answer = protected home network that I can access remotely WHILE keeping all traffic to/from anonymized on all devices.

  1. Got just about everything working via FQDN (w/port forwarding and the like.) This has been an on-again/off-again effort over the years (bits & pieces working, never full solution.) Objective of getting access to home network while keeping traffic anonymized. Goal accomplished. (Have to take a moment for a mental celebration of actually achieving this goalā€¦before abandoning it all.) While effective, it leaves the system more exposed than desired. While getting ready to put it all into reverse proxy mode, through the journey, discovered TailScale. Just got that working and, well, it is pretty slick. Handles everything.

  2. While TS is working, few glitches to iron out in terms connectivity.

Next steps are to get TS connected to domain, tidy up the network (all the experiments to delete,) automate data backups, start getting the docker/media server up and running and then locking down the network.

Appreciate the response thanks, but where is the anonymization?
How are you (defining) and addressing that? I think that is the crux
of my confusion.

3rd party vpn (think Nord) through shared encrypted traffic services.

I can get this working through the port forward/ddns hosting. Hitting a glitch on iOS using TailScale.

Update:

Got everything working as hoped. Essentially boils down to TailScale to keep
Connected to home network and the whitelisting the TailScale IPs in the vpnā€¦so all traffic remains encrypted and still accessing home network. Magical.

Turned off all the port forwards, disabled all the access pointsā€¦so much cleaner, simpler and secure.

4 Likes