Jump to content

Got my internet upgraded to public ip for NAS and NVR , how to make sure my network are secure ?

TukangKopi

Hi i'm kinda new for networking stuff and still very confused, got a plan to upgrade my home internet to the public one, which is faster, and i need outside connection to my NVR and NAS , do i need set up firewall or anything after the upgrade ? and how to make sure my internet secure ?

Link to comment
Share on other sites

Link to post
Share on other sites

You HAVE to set up a firewall if you want to expose ports to internet. Considering your lack of experience is showing up in the OP, I would recommend hosting a VPN server instead of exposing everything to internet.

mY sYsTeM iS Not pErfoRmInG aS gOOd As I sAW oN yOuTuBe. WhA t IS a GoOd FaN CuRVe??!!? wHat aRe tEh GoOd OvERclok SeTTinGS FoR My CaRd??  HoW CaN I foRcE my GpU to uSe 1o0%? BuT WiLL i HaVE Bo0tllEnEcKs? RyZEN dOeS NoT peRfORm BetTer wItH HiGhER sPEED RaM!!dId i WiN teH SiLiCON LotTerrYyOu ShoUlD dEsHrOuD uR GPUmy SYstEm iS UNDerPerforMiNg iN WarzONEcan mY Pc Run WiNdOwS 11 ?woUld BaKInG MY GRaPHics card fIX it? MultimETeR TeSTiNG!! aMd'S GpU DrIvErS aRe as goOD aS NviDia's YOU SHoUlD oVERCloCk yOUR ramS To 5000C18

Link to comment
Share on other sites

Link to post
Share on other sites

I would never recommend exposing your NAS.

I work in IT and the Amount of Endusers who did this and got their QNAP ransomwared is insane...

 

I myself expose some Services from my Homenetwork, but those are behind a Reverse Proxy, have 2FA set up and are in their own VLAN, so if something does happen, it will not be able to spread.

 

If you do not have experience with exposing anything to the public, please concider putting everything behind a VPN.

My Gaming PC:
Inno3D iChill Black - RTX 4080 - +500 Memory, undervolted Core, 2xCorsair QX120 (push) + 2xInno3D 120mm (pull)
AMD Ryzen 7 7800X3D - NZXT x72
G.SKILL Trident Z @6000MHz CL30 - 2x16GB
Asus Strix X670E-E Gaming

1x500GB Samsung 960 Pro (Windows 11)

1x2TB Kingston KC3000 (Games)

1x1TB WD Blue SN550 (Programs)

1x1TB Samsung 870 EVO (Programs)
Corsair RM-850X

Lian Li O11 Vision
Alienware 360 HZ QD-OLED AW2725DF, MSI Optix MAG274QRFDE-QD, BenQ ZOWIE XL2720

Logitech G Pro Wireless Superlight
Wooting 60HE

Audeze LCD2-C + FiiO K3

Klipsch RP600-M + Klipsch R-120 SW

 

My Notebook:

MacBook Pro 16 M1 - 16GB

 

Proxmox-Cluster:

  • Ryzen 9 3950X, Asus Strix X570E F-Gaming, 4x32GB3200MHz ECC, 2x 512GB NVMe ZFS-Mirror (Boot, Testing-VMs + TrueNAS L2ARC), 2x14TB ZFS-Mirror + 1x3TB (TrueNAS-VM), 1x 1TB Samsung 980 Pro NVMe (Ceph-OSD), 10G NIC
  • i7 8700k delidded undervolted, Gigabyte Z390 UD, 4x16GB 3200MHz, 1x 512GB SSD (Boot), 1x 1TB Samsung 980 Pro NVMe (Ceph-OSD), 10G NIC
  • i5 4670, 3x4GB + 1x8GB 1600MHz, 1x 512GB SSD (Boot), 1x 1TB Samsung 980 Pro NVMe (Ceph-OSD), 10G NIC

Proxmox-Backup-Server:

  • i5 4670, 4x4GB 1600MHz, 2x2TB ZFS-Mirror, 2,5G NIC
Link to comment
Share on other sites

Link to post
Share on other sites

Agreed with both previous comments :

- Don't expose your NAS or any devices on Internet if you don't have experience doing that,

- Use a firewall and a VPN,

I'd add :

- Before you open anything to the internet, check the documentation of the thing your opening, they most of the time have security consideration that you can look up,

- Be up to date on that device/software, and keep it up to date,

- Once you open access to something from the " outside world " (the internet), verify your logs, check what's happening there, some insight will be spotable,

- Don't forget to backup your data 😉 Firewall / VPN aren't perfect, Raid is not a backup, and the internet is full of evil.

 

(Ho and context for the knowledge : I work for an ISP, we have tools to scan our network, and discover a lot of interesting things frequently 😉 )

Link to comment
Share on other sites

Link to post
Share on other sites

Thx for the info, yep i'll stay within private ip package for sometimes haha 😅, is it enough tho to use base mikrotik firewall ? if i upgraded to public ip but i didn't link any of my device to outside network ? but using a simple portforward ?

Link to comment
Share on other sites

Link to post
Share on other sites

On 5/13/2024 at 6:02 AM, TukangKopi said:

Thx for the info, yep i'll stay within private ip package for sometimes haha 😅, is it enough tho to use base mikrotik firewall ? if i upgraded to public ip but i didn't link any of my device to outside network ? but using a simple portforward ?

I'm not so familiar with Mikrotik's firewall, however I know a friend use it on a decently big infra without any issues. If the option is available there, maybe filter based on location / country, also don't use the default ports for your services. (Security by obscurity isn't that good, but it's a start). 

 

However my advice would be :

- Always prefer a VPN, so the " only " open port on your router/firewall is the VPN.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×