logo elektroda
logo elektroda
X
logo elektroda

Access to the NAS from the outside without a public IP

noel200 9432 49
ADVERTISEMENT
Treść została przetłumaczona polish » english Zobacz oryginalną wersję tematu
  • #31 19570276
    Anonymous
    Level 1  
  • ADVERTISEMENT
  • #32 19570327
    voxck
    Level 9  
    Really. Colleague @Erbit wrote well. The principle of operation of Zerotier is slightly different than I wrote earlier. I had time to delve deeper into the description of the service. Sorry for spreading misinformation.
  • ADVERTISEMENT
  • #33 19570334
    noel200
    Level 27  
    voxck wrote:
    Really. Colleague @Erbit wrote well. The principle of operation of Zerotier is slightly different than I wrote earlier. I had time to delve deeper into the description of the service. Sorry for spreading misinformation.

    I've read now and apparently the external server is only used to set up the connection, and then everything goes p2p.
    Well, but some external apps and servers are always an additional leak point.
  • #34 19570341
    voxck
    Level 9  
    noel200 wrote:

    I've read now and apparently the external server is only used to set up the connection, and then everything goes p2p.
    Well, but some external apps and servers are always an additional leak point.


    Even apart from the technical side, it is a very useful service. This is how I have a PLEX issued for my family. I don't really feel like opening ports so in this case Zerotier works great.
  • #35 19570405
    Anonymous
    Level 1  
  • #36 19570419
    voxck
    Level 9  
    Erbit wrote:

    So that it's not that I'm so "bad" I will add that this is a very good solution, especially when there is no public IP . It is simply impossible to run your own VPN server without a public IP and then the connection must be initiated "from the inside of the network".


    It's not about 'bad' or 'good' :) . A master server is needed to establish a connection. Hosts don't initiate connection directly with each other (as I thought before) and you were right of course here, because you need a server between them.

    And the service itself is great. I've been using it for a long time and it works really great. Particularly useful, for example, when you want to put even Pihole outside the LAN and have Internet filtering outside the house (and in combination with unbound DNS) it works very well. And that's without opening ports on the router.
  • ADVERTISEMENT
  • #37 19570424
    Anonymous
    Level 1  
  • ADVERTISEMENT
  • #38 19572288
    noel200
    Level 27  
    I just tried setting up a VPN. On the router, in the VPN server tab, there are PPTP and OPENVPN. First, I set up PPTP. On the phone with Android 10 and the MIUI 12 overlay, I set a new VPN profile. I selected PPTP there, entered the user and password as on the router. I also gave the server address, i.e. my IP from dyndns. PPP (MPPE) encryption is also set on the phone. I turned it on and it showed that it was connected. The router also shows that there is a connection.
    I have disabled port forwarding on the NAS and from a phone with WiFi disabled, I cannot access the NAS service pages. Doesn't work :( Maybe you need to enter something else in the browser? another port? Or in the router some redirection to this VPN?
    I also tried on the OpenVPN router. I set the user and pass, exported the .ovpn file. I installed the OpenVPN connect app on the phone, loaded this file, gave the user and pass and the effect is the same. What can I be doing wrong? There is no IPSec on this firmware in Asus.
  • Helpful post
    #39 19572294
    Anonymous
    Level 1  
  • #40 19572316
    noel200
    Level 27  
    Erbit wrote:
    What IP did you get after logging in?

    Using PPTP on the whatismyip site I have the same address as the router and PC connected at home. But this is not the address I got from the ISP. As I wrote earlier, they still have some NAT redirects? the address shows 109.231.7.x, but from the ISP I have a permanent address 10.9.209.x.dyndns.xxxx.pl.
    Is that why it doesn't work?
    Erbit wrote:
    What's your NAT address?

    This question is probably related to the first one, and I hope I answered above, but I don't know that much.

    Added after 2 [minutes]:

    Erbit wrote:
    When configuring the OpenVPN server, what did you choose?
    Code: Client will use to access:
    - local only
    - internet + local

    "both"
  • Helpful post
    #41 19572328
    Anonymous
    Level 1  
  • #42 19572350
    noel200
    Level 27  
    Erbit wrote:
    When logging in to the NAS, do you use its IP or domain name?

    Remotely, when I enter NAS services, I enter 10.9.209.x.dyndns....:xxx on the phone, and I have port forwarding enabled on the router.
    I guess I'm left with the zerotier. I read, I registered, I have a network id, I installed it on the phone. He did on the VPN phone and connected to the remote server. But I don't know how to install it on OMV.
    Probably via docker, but I have no idea what to type there. With the rest, if the service fails in a month or two, it will be a pile.
    Or maybe WinSCP?
    Quote:
    zerotier is one option, others can be use a VPN, or most simple, use WinSCP to access from outside of your LAN to your data

    (quoted from the openmediavault forum.)
    But isn't that Putty? to SSH?

    Added after 25 [minutes]:

    In the DDNS tab on the router, I changed the "Method to retrieve WAN IP" option from external to internal but it did not help.
  • Helpful post
    #43 19572466
    Anonymous
    Level 1  
  • #44 19572479
    noel200
    Level 27  
    Erbit wrote:
    You must use a local NAS address. A VPN "has taken you inside the network".

    It actually works :) But terribly slow :(
  • #45 19572499
    Anonymous
    Level 1  
  • #46 19572503
    noel200
    Level 27  
    Erbit wrote:
    Slower than ddns and redirection?

    Definitely slower. The emba page has not yet loaded.
    Erbit wrote:
    Maybe set PPTP server and check then.

    I've just done that.
  • #47 19574015
    Anonymous
    Level 1  
  • #48 19575934
    noel200
    Level 27  
    Erbit wrote:
    Do you also use IP or domain while connected to WiFi?

    If I have VPN enabled on my phone, it's from IP.
    Now I checked and it works faster. Movies in 4k@60fps take a long time to load, but photos of 10MB on average take 1-2s to load.
    So it's probably as good as it can be.
    Thank you for your help. I'm not closing the issue. I will probably still have some questions and problems.
  • #49 19575939
    Anonymous
    Level 1  
  • #50 19575950
    noel200
    Level 27  
    Erbit wrote:
    I want to know if you are using IP when you are connected to WiFi.

    Yes. If I understood the question correctly.

Topic summary

Accessing a NAS (Network Attached Storage) device externally without a public IP can be achieved through various methods. Users discussed the necessity of a public IP or alternatives like Dynamic DNS (DDNS) to maintain consistent access. The conversation highlighted the importance of configuring a VPN server on the router (specifically Asus routers with AsusWRT) to securely connect to the NAS. Users shared experiences with different VPN protocols, including PPTP and OpenVPN, and emphasized the need for port forwarding to access NAS services. Additionally, Zerotier was suggested as a viable solution for users without a public IP, allowing for easy configuration and direct device access. The discussion also touched on upload speeds and potential performance issues when accessing media files remotely.
Summary generated by the language model.
ADVERTISEMENT