Why you might want to block outside IPs on your Synology NAS

A Synology NAS is a network storage device that sits on your home or office network and holds files you access remotely. By default, anyone with your login credentials can connect from anywhere in the world — a coffee shop in Tokyo, an airport in Berlin, or anywhere else with internet. If you want only people physically near you (or in your country) to access your NAS, you can restrict connections by geographic location using IP blocking.

This is different from a password. A password stops someone who doesn't know it. IP blocking stops someone whose internet connection originates from outside your chosen region, even if they have the right password. The two work together: password protects against guessing, IP blocking protects against access from unwanted locations.

Synology does not have a built-in "block by country" feature in the main interface. Instead, you block specific IP ranges or use a firewall rule. The method depends on whether you want to block all outside traffic or just certain services like remote access.

Key Takeaways

  • Synology NAS does not have a country-level blocking feature in the settings menu — you must use firewall rules or IP blocking instead.
  • The easiest method is to deny all inbound traffic in the Firewall settings, then allow only your home network's IP address or a specific range.
  • If you need to block by country rather than by specific IP, you will need to manually add IP ranges for countries you want to exclude, which requires a list of those ranges.
  • Blocking traffic affects remote access services like QuickConnect and WebDAV, so test your own access after making changes to avoid locking yourself out.

Block all outside traffic using the Firewall

The simplest way to stop international access is to use Synology's built-in Firewall to deny all inbound connections, then add exceptions for IPs you trust. This works whether you want to block by country or just block everything except your home network.

Open DSM (the Synology control panel) on your NAS. Go to Control Panel > Security > Firewall. You will see a list of rules. By default, most Synology systems allow all inbound traffic. Click Edit Rules to change this.

At the bottom of the rules list, find the default rule (usually labeled "All" or "Default"). Change its action from Allow to Deny. This blocks all incoming connections from outside your network. Now add a new rule above it: click Create, set the source to your home IP address or home network range, set the destination port to the services you use (usually port 5000 for HTTP or 5001 for HTTPS), and set the action to Allow. Click OK and then Apply.

Your NAS will now reject all outside connections except from the IP address or range you specified. If you travel and need to connect from a different location, you will need to add that IP to the allow list, or temporarily change the firewall rule. This is why knowing your home IP address matters — if it changes (which it does for most home internet), your remote access will stop working.

Block by country using IP ranges

If you want to block entire countries rather than just all outside traffic, you need to add firewall rules for the IP ranges used in those countries. This is more complex because IP ranges are large and change over time, and you must add them manually.

First, find a list of IP ranges for the countries you want to block. Websites like ipdeny.com publish free lists of IP ranges by country in a format you can use. Download the list for each country you want to block (for example, download the file for China, Russia, or any other country).

In Synology Firewall, you can add rules one at a time, but with hundreds of IP ranges per country this becomes impractical. A better approach is to use the Synology command line (SSH) to add rules in bulk. This requires enabling SSH access on your NAS first: go to Control Panel > Terminal & SNMP, check Enable SSH service, and note the port number (usually 22). Then use an SSH client on your computer to connect and paste commands that add the IP ranges as firewall rules.

If you are not comfortable with the command line, the manual approach is to add the largest or most critical IP ranges as individual firewall rules. Focus on the ranges that represent the most traffic from countries you want to block, rather than trying to block every single range.

Block specific services instead of all traffic

You may not want to block all outside access — you might want to allow some services (like a cloud backup) but block others (like remote file access). In that case, create firewall rules for individual services instead of a blanket deny.

In the Firewall rules, each rule can target a specific port or service. For example, QuickConnect (Synology's remote access service) uses port 6900. WebDAV uses port 5005. SSH uses port 22. Create a deny rule for the ports you want to block from outside, and leave other ports open.

This approach is more flexible but requires you to know which port each service uses. Check Synology's documentation for the service you want to restrict, find its port number, and add a deny rule for that port with a source of "All" or a specific country's IP range.

Test your changes before locking yourself out

After you add firewall rules, test them immediately from a device outside your network. Try to access your NAS using QuickConnect, a web browser, or whatever method you normally use. If the connection fails, you may have blocked yourself.

If you cannot access your NAS from outside and you did not intend to block yourself, you have a few options. If you are at home on your local network, log into DSM directly and adjust the firewall rules. If you are away from home, you may need to ask someone at home to change the rules for you, or wait until you return home to fix it.

This is why it is safer to start with a small change — block one country or one service first, test it, and then expand the rules. Do not block everything at once and then test.

Use a VPN if you travel but want to stay blocked

If you travel frequently and want your NAS to remain blocked to outside IPs, you can use a VPN (virtual private network) to make your connection appear to come from your home country or home network. A VPN routes your traffic through a server in a location you choose, so your NAS sees the VPN server's IP instead of your actual location.

To use this method, subscribe to a VPN service, install the VPN client on your laptop or phone, connect to the VPN before accessing your NAS, and then access your NAS as normal. Your NAS will see the VPN server's IP address, which you can add to your firewall allow list. This way, you stay protected from outside access while still being able to reach your NAS from anywhere.

Note that a VPN adds a step to your access routine and may slow your connection slightly, depending on the VPN service. It is most useful if you travel occasionally rather than constantly.

Frequently Asked Questions

Will blocking outside IPs stop hackers from accessing my NAS?

IP blocking stops connections from outside your chosen region, but it is not a complete security solution. A hacker with your password can still connect if their IP is in an allowed range. Use IP blocking along with a strong password, two-factor authentication, and keeping your Synology software updated.

What if my home internet IP address changes?

Most home internet providers assign a new IP address periodically (usually every few days or months). If you block all outside traffic except your home IP, and your IP changes, you will lose remote access. To avoid this, allow your entire home network range instead of a single IP, or use a VPN to connect from outside.

Can I block by country without using the command line?

Yes, but it is slow. You can add IP ranges one at a time in the Firewall rules interface. However, each country has hundreds of IP ranges, so blocking even one country manually takes hours. The command line method is much faster if you are comfortable with it.

Does blocking IPs affect my local network access?

No. Firewall rules apply only to traffic coming from outside your local network. Devices on your home network can always access your NAS, regardless of firewall settings.

What is QuickConnect and will blocking IPs affect it?

QuickConnect is Synology's service that lets you access your NAS remotely without setting up port forwarding. If you block all outside traffic, QuickConnect stops working. If you block by country, QuickConnect works for people in allowed countries. You can also create a firewall rule that blocks QuickConnect specifically while allowing other services.