What is the default firewall

IPv4/6, Port, VPN, proxy, SSH, remote access and more.
Locked
User avatar
davenovo
Posts: 1
Joined: 24 Oct 2023, 16:17

What is the default firewall

Post by davenovo »

Hello,
When I go to Control Panel->Security->Firewall I do not see any firewall rules present. Does that mean that by default the firewall is not active? If the firewall is active, what are the default rules?

I had presumed (perhaps incorrectly) that a firewall was active allowing only port 80. So I added a rule to allow port 8080, but that seems to have locked me out of using the NAS and I had to reset it.

Some forum posts said that there was only a single "allow" rule. Is that true? If so, what ports do I have to ensure that I allow in order to not lock myself out.
User avatar
TMzethar
TerraMaster Team
Posts: 1280
Joined: 27 Oct 2020, 16:43

Re: What is the default firewall

Post by TMzethar »

When there are no rules, the firewall defaults to fully allowed.
To contact our team, please send email to following addresses, remember to replace (at) with @:
Technical team: support(at)terra-master.com (for technical support)
Service team: service(at)terra-master.com (for purchasing, return, replacement, RMA service)
User avatar
Gremlin
Posts: 493
Joined: 02 Dec 2022, 22:31
Great Britain

Re: What is the default firewall

Post by Gremlin »

But:

When you add an "allow" rule you actually generate:

Allow: 8080
Deny: All (the rest)

Since the rules are read in order.
What you allow will depend on what is running on your NAS.

{Based on my limited experience of unix and the odd router firewalls I have worked with. YMMV ;) }
F5-221 5.1.123, 8GB System Partition on 3 x 4TB Traid; 3TB EXT4
F2-221 TOS6 (Beta), 8GB System Partition on 2 x 6TB in Traid. (Latest Update 11/04/24)
User avatar
TMqiky
Posts: 51
Joined: 07 Aug 2023, 18:10

Re: What is the default firewall

Post by TMqiky »

The firewall is fully open by default.
Setting "Disable" will block the specified IPs and "Allow" will block other unallowed IPs.
The firewall can only choose to use "Disable" or "Allow" at the same time. If you don't need to connect to the Internet, you can directly enable "Secure Isolated Mode", which will automatically set up a firewall for you that only the LAN can access. If you are not sure which IPs can be blocked, it is recommended to use "Block" to block the range of IPs that you don't need.
The following are some of the known IP segments that cannot be disabled:
Device itself 127.0.0.1
Application center hub: 47.90.0.247
tnas.link: 119.28.31.72
cn.tnas.link: 106.14.61.188
us.tnas.link: 47.254.40.125
eu.tnas.link: 8.209.75.86
You can learn more at the following link
viewtopic.php?f=78&t=4895
To contact our team, please send email to following addresses, remember to replace (at) with @
Technical team: support(at)terra-master.com (for technical support)
Service team: service(at)terra-master.com (for purchasing, return, replacement, RMA service)
Locked

Return to “Network & Remote Access”