Does enabling QuFirewall on home network make sense?

Questions about SNMP, Power, System, Logs, disk, & RAID.
Post Reply
Freeco
New here
Posts: 4
Joined: Fri Jul 31, 2020 7:07 pm
Location: Belgium

Does enabling QuFirewall on home network make sense?

Post by Freeco »

When QuFirewall is running the disks in my TS453D no longer go in standby mode. The passed few months every time I passed by the NAS the disks were spinning.
When I stop QuFirewall the disks are regularly spun down, which is what I want.

So... on a home network, does it make sense to have QuFirewall on? My NAS is behind my ISP router, which also has an active FW.
I don't use port forwarding or uPNP, and I keep Download Station in stopped state when not used. When I use Download Station (which is not frequently), I then also start QuFirewall. I don't have any other tools on my NAS that connect to the internet.

Should be OK, I guess?
User avatar
dolbyman
Guru
Posts: 35248
Joined: Sat Feb 12, 2011 2:11 am
Location: Vancouver BC , Canada

Re: Does enabling QuFirewall on home network make sense?

Post by dolbyman »

no need for QuFirewall when behind a NAT .. and the NAS should always be behind a NAT (so QuFirewall can be uninstalled and forgotten)
User avatar
Moogle Stiltzkin
Guru
Posts: 11448
Joined: Thu Dec 04, 2008 12:21 am
Location: Around the world....
Contact:

Re: Does enabling QuFirewall on home network make sense?

Post by Moogle Stiltzkin »

i use a pfsense firewall. the qufirewall i just enable though i don't rely need it, to limit access to other lan ips on network (though i've already setup vlans to separate iots from other devices so probly not rely needed either)

when i suspect an issue for access to qnap, these days i'd first suspect the qufirewall and disable to check if that resolves the issues. but the rule setting i have seems to work fine no issue.

if u don't use qufirewall, it reverts back to the previous network security settings for the QNAP to handle things like ip/blocking for failed attempts to login with credentials. This is the change if u opt to disable qufirewall.

if ur protecting ur home network from internet, rely on something solid like pfsense on a router for that *default settings for it is already good, though u need to change password and some minor setup as per youtube guides online.

even with qufirewall disabled, the reverted network security options in qnap still gives u the option to setup white/black listing for ips, if u want to restrict access on your lan. but since qufirewall works as well, i just use that. It's up to u which works best for u ^^


oo and don't expose your nas online. e.g. don't enable upnp on router, and nas (and anything for that matter). And don't port forward unless there is a good reason to do so :S

remote access to the nas over the internet should ideally be done via vpn which you configure a vpn server ideally on your router. But if you don't have remote access requirements then that's far easier, as long as u don't expose ur nas, and u update regularly enough, and maintain a clean network (u don't download malware and stuff), and you keep regular backups, then you should be fine :D


anyway there is already an indepth discussion for qufirewalls usefulness, u should check it out here
https://www.reddit.com/r/qnap/comments/ ... o_protect/
NAS
[Main Server] QNAP TS-877 (QTS) w. 4tb [ 3x HGST Deskstar NAS & 1x WD RED NAS ] EXT4 Raid5 & 2 x m.2 SATA Samsung 850 Evo raid1 +16gb ddr4 Crucial+ QWA-AC2600 wireless+QXP PCIE
[Backup] QNAP TS-653A (Truenas Core) w. 4x 2TB Samsung F3 (HD203WI) RaidZ1 ZFS + 8gb ddr3 Crucial
[^] QNAP TL-D400S 2x 4TB WD Red Nas (WD40EFRX) 2x 4TB Seagate Ironwolf, Raid5
[^] QNAP TS-509 Pro w. 4x 1TB WD RE3 (WD1002FBYS) EXT4 Raid5
[^] QNAP TS-253D (Truenas Scale)
[Mobile NAS] TBS-453DX w. 2x Crucial MX500 500gb EXT4 raid1

Network
Qotom Pfsense|100mbps FTTH | Win11, Ryzen 5600X Desktop (1x2tb Crucial P50 Plus M.2 SSD, 1x 8tb seagate Ironwolf,1x 4tb HGST Ultrastar 7K4000)


Resources
[Review] Moogle's QNAP experience
[Review] Moogle's TS-877 review
https://www.patreon.com/mooglestiltzkin
User avatar
jaysona
Been there, done that
Posts: 854
Joined: Tue Dec 02, 2008 11:26 am
Location: Somewhere in the Great White North

Re: Does enabling QuFirewall on home network make sense?

Post by jaysona »

Freeco wrote: Fri Aug 12, 2022 9:37 pm When QuFirewall is running the disks in my TS453D no longer go in standby mode. The passed few months every time I passed by the NAS the disks were spinning.
When I stop QuFirewall the disks are regularly spun down, which is what I want.
There may be other services writing to logs besides QuFirewall, get a copy of IOtop to what other processes are writing to disk as well.
So... on a home network, does it make sense to have QuFirewall on? My NAS is behind my ISP router, which also has an active FW.
QuFirewall does not make sense in any enviuronment, it is just a p.o.s software that serves more use of providing a false sense of the warm and fuzzies vs providing any real security benefit at all.

As dolbyman stated, QuFirewall can be uninstalled and forgotten when a NAS is used in a home network environment - with the following caveats (you've donme that already, so good, this is for other readers): Disable UPnP on the NAS, disable UPnP on the Internet router, make sure tcp 8080 and tcp 443 are not forwarded to the NAS from the Internet router.
....
Should be OK, I guess?
Yes, should be more than okay,
RAID is not a Back-up!

H/W: QNAP TVS-871 (i7-4790. 16GB) (Plex server) / TVS-EC1080 (32Gig ECC) - VM host & seedbox
H/W: Asustor AS6604T (8GB) / Asustor AS7010T (16GB) (media storage)
H/W: TS-219 Pro / TS-509 Pro
O/S: Slackware 14.2 / MS Windows 7-64 (x5)
Router1: Asus RT-AC86U - Asuswrt-Merlin - 386.7_2
Router2: Asus RT-AC68U - Asuswrt-Merlin - 386.7_2
Router3: Linksys WRT1900AC - DD-WRT v3.0-r46816 std
Router4: Asus RT-AC66U - FreshTomato v2021.10.15

Misc: Popcorn Hour A-110/WN-100, Pinnacle Show Center 250HD, Roku SoundBridge Radio (all retired)
Ditched QNAP units: TS-269 Pro / TS-253 Pro (8GB) / TS-509 Pro / TS-569 Pro / TS-853 Pro (8GB)
TS-670 Pro x2 (i7-3770s 16GB) / TS-870 Pro (i7-3770 16GB) / TVS-871 (i7-4790s 16GB)
Post Reply

Return to “System & Disk Volume Management”