• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Synology DDNS not work

DHCP and DNS
2
15
2.8k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • G
    Guazo
    last edited by May 15, 2020, 11:21 AM

    Hi,

    just installed pfsense and connect my Synology Nas to Lan. I can access to nas via lan and via Internet with http://name.synology.me:5000 but something goes wrong if i try to connect with name.synology.me.

    1 Reply Last reply Reply Quote 0
    • D
      DaddyGo
      last edited by May 15, 2020, 11:52 AM

      Synology behind pfSense is a strange animal pairing, but it works if you consider a few things.
      https://www.synology.com/en-global/knowledgebase/DSM/tutorial/Network/What_network_ports_are_used_by_Synology_services

      To use Synology DDNS, you need port forward to port 443

      Since Synology uses CDN worldwide, make sure your Synology account is active in this menu.

      login-to-view

      login-to-view

      Cats bury it so they can't see it!
      (You know what I mean if you have a cat)

      1 Reply Last reply Reply Quote 0
      • D
        DaddyGo
        last edited by May 15, 2020, 12:26 PM

        what I forgot: ☺
        in many cases it may be necessary and I suggest that:
        https://www.synology.com/en-global/knowledgebase/DSM/help/DSM/AdminCenter/connection_certificate

        Cats bury it so they can't see it!
        (You know what I mean if you have a cat)

        1 Reply Last reply Reply Quote 0
        • G
          Guazo
          last edited by May 15, 2020, 1:05 PM

          Just did certificate.
          Synology working fine when i connect it directly to router\modem. Only when i connect it behind Pfsense i cannot use xxx.synology.me

          Just tried to forward port 443 but nothing change

          1 Reply Last reply Reply Quote 0
          • D
            DaddyGo
            last edited by May 15, 2020, 1:20 PM

            This is perfectly normal since pfSense is a firewall, not a SOHO router.
            Try this trick, more of our Synology NAS works this way:

            hybrid outbound NAT for Syno

            login-to-view

            if Synology can't reach its own CDN network, it can't do a lot of things, can't update packages, or antivirus package, for example....
            (this is a known problem or Synology wants just that)

            Above you mentioned you're trying to connect on http, That's why I suggested https + Let'sEnc / this can be seen in the linked description that it is also required for the DDNS provided by Synology, as it is Synology's own service, i.e. CDN .....

            Cats bury it so they can't see it!
            (You know what I mean if you have a cat)

            1 Reply Last reply Reply Quote 0
            • D
              DaddyGo
              last edited by DaddyGo May 15, 2020, 1:31 PM May 15, 2020, 1:26 PM

              Don't forget, if you are also running IPS / IDS or pfBlockerNG, keep an eye on the logs for what is preventing the NAS from accessing your own CDN network.
              This will be clearly visible in the logs....

              (jahhh and it varies from country to country and region to region.
              Synology tech support couldn’t even give me an IP range (for country CDN) when I first encountered this problem.) 😕

              Cats bury it so they can't see it!
              (You know what I mean if you have a cat)

              1 Reply Last reply Reply Quote 0
              • G
                Guazo
                last edited by May 15, 2020, 1:50 PM

                Ok seems snort blocked my public IP.

                I quit snort and now, as before, i can reach Nas typing https://name.synology.me/5001or http://name.synology.5000. If i try with name.synology.me give me error 403

                1 Reply Last reply Reply Quote 0
                • D
                  DaddyGo
                  last edited by DaddyGo May 15, 2020, 2:05 PM May 15, 2020, 2:02 PM

                  This is not very good, if your Snort config have blocked the WAN public IP because it means it is misconfigured...

                  This parameter is important to Snort / Suricata (this setting does not allow blocking of WAN IP + gateways, DNS servers, etc.):

                  login-to-view

                  Yes, yes the DSM port (5000 or 5001) is also important in the connection header 😉

                  Cats bury it so they can't see it!
                  (You know what I mean if you have a cat)

                  1 Reply Last reply Reply Quote 0
                  • G
                    Guazo
                    last edited by May 15, 2020, 2:10 PM

                    Check, Snort parameters are on default for each two voices

                    1 Reply Last reply Reply Quote 0
                    • D
                      DaddyGo
                      last edited by May 15, 2020, 2:13 PM

                      What does the View List show?

                      login-to-view

                      and

                      login-to-view

                      Cats bury it so they can't see it!
                      (You know what I mean if you have a cat)

                      1 Reply Last reply Reply Quote 0
                      • G
                        Guazo
                        last edited by Guazo May 15, 2020, 2:47 PM May 15, 2020, 2:47 PM

                        No data here

                        1 Reply Last reply Reply Quote 0
                        • D
                          DaddyGo
                          last edited by May 15, 2020, 3:07 PM

                          Then this is exactly the problem with the basic configuration, you have to think through where you made a mistake during the installation.
                          Only based on these parameters does the firewall know who is inside and who is outside (and who shall not be harmed), so the entire firewall is malfunctioning.

                          Cats bury it so they can't see it!
                          (You know what I mean if you have a cat)

                          1 Reply Last reply Reply Quote 0
                          • G
                            Guazo
                            last edited by May 15, 2020, 3:12 PM

                            One problem is solved, the firewall in my modem was still active and blocked port 80 😡 now i can connect to nas via web using name.synology.me

                            About snort how i can solve the problem? Do you suggest to unistall and reinstall snort?

                            1 Reply Last reply Reply Quote 0
                            • D
                              DaddyGo
                              last edited by May 15, 2020, 4:03 PM

                              It may be a good start at first,
                              since IPS / IDS works based on $ HOME_NET and $ EXTERNAL_NET, as shown here, for example the structure of a rule is such:

                              login-to-view

                              but I suspect there are several problems with NGFW configuration, interfaces, DNS setup, etc

                              Cats bury it so they can't see it!
                              (You know what I mean if you have a cat)

                              1 Reply Last reply Reply Quote 0
                              • D
                                DaddyGo
                                last edited by May 15, 2020, 4:07 PM

                                For security reasons only, external http (80) connections are not appropriate, especially for a NAS, use https, if you want to access the NAS remotely.
                                Or use Syno's built-in OpenVPN package for external access

                                Cats bury it so they can't see it!
                                (You know what I mean if you have a cat)

                                1 Reply Last reply Reply Quote 0
                                3 out of 15
                                • First post
                                  3/15
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.