[First setup][Security] Is this setup good enough or does it have bottlenecks?

Discussion on setting up QNAP NAS products.
Post Reply
averageJohn
First post
Posts: 1
Joined: Thu Nov 25, 2021 8:43 pm

[First setup][Security] Is this setup good enough or does it have bottlenecks?

Post by averageJohn »

Hi all :),
First of all, I want to say that I lurked this forum for a bit and I'm impressed with the number of useful tips and overall genuine help provided. I also have a "small" batch of questions but let's start with some info.

HARDWARE
Device: TS-473A
RAM: 2x8GB (right now I don't remember which model but it was something decent)
OS: QTS 5.0.0.1858
HDD: 4x8TB WD RED Plus (WD80EFBX-68AZZN0)
SSD: 1x250GB Kingston A2000 2 NVMe

NAS usage
1. File storage for ~10 users - a lot of huge files (.psd projects, Corel stuff, high quality videos etc.) would be uploaded (or transferred from a USB drive) in batch. For those files, NAS will be a backup device and users could be connected to NAS via shared folder (SMB) with proper permissions etc.
2. VPN (Wireguard prefered but OpenVPN or QVPN should be ok too) that would be reachable from outside. Yes, I know, I have to do a port forwarding on a router and I have static IP so I don't think that DDNS is needed?
3. 1 Windows 10 VM that should be reachable (RDP preferred) if a client is connected via VPN.
4. 10-15 users would use it as a local "cloud" for documents and other small (couple MB) files - here I'm thinking about Qsync or Nextcloud but IDK which would be better.
5. RAID - as it is a 4 bay NAS and I'm on the budget I want to use RAID 5 with regular backups of important data to a portable drive.
6. Backup of 4-5 Win 10 workstations.

My questions
1. As I'm a bit paranoid I want to set it up in a way that only a person from a LAN or connected via VPN could reach admin panel or any services that are running on NAS. If I would forward only one port for VPN it should be fine, right? *myqnapcloud.com login link is NOT configured on purpose.
2. I read that if I disable default "admin" account I'll not be able to SSH to a NAS. Is it still true?
3. I really don't know what to do with this single SSD drive. I could do a mirror of it every week or so if I'll use it as a system drive to not be totally screwed when it will die or I could use it as read-only cache. What do you guys think? Yes, I know that OS on SSD should be on RAID 1 for obvious reasons...
4. As I'm already maxed out in terms of HDDs should I go for one thick volume or maybe static volume would be better?
5. In terms of network I currently have only 100mbps switches - I want to connect all heavy users to 1gbit switch early next year.
6. Should I switch to QuTS with only 16GB of RAM? I saw that it had deduplication and other neat features but I heard that file sharing might be more complex. ZFS > EXT4 ;).
6. This is my first NAS so if you think something is clearly wrong with this setup - feel free to point it out.

Thanks in advance for all the replies :).
Post Reply

Return to “Turbo Station Installation & Setup”