How to Set Up a VPN Server on Your Synology NAS
A Synology NAS can do much more than store files on your home network. With a Virtual Private Network (VPN) server, you can create an encrypted connection back to your NAS and access shared folders, backups, media libraries and selected home services while travelling or working away from home.
For Australian households and small businesses, this can be useful when connecting from a café in Melbourne, a hotel in Cairns or a worksite outside Perth. It also gives you a safer alternative to exposing DSM, File Station or other NAS services directly to the public internet.
Check Your NAS, Network And Remote Access Needs
Start by confirming that your Synology model supports the VPN Server package available through Package Center. Sign in to DSM, open Package Center, search for VPN Server, and install the package. Update DSM and the package first, because VPN security depends on current software and reliable encryption libraries.
You also need administrator access to your home router. The NAS should have a fixed local IP address, either configured manually or reserved through DHCP. A stable address such as 192.168.1.20 makes port forwarding dependable after a router reboot.
Think about how you will use the connection. If you only need files while away, a full network tunnel may be unnecessary. If you want to reach a printer, backup target, Plex library or home automation device as well, a VPN that routes traffic to your local network is more useful.
Australian internet connections can add an extra complication. Some NBN providers place customers behind Carrier-Grade NAT, which prevents ordinary inbound port forwarding. If your router’s internet address does not match the address shown by an external IP-checking service, ask your ISP about a public IPv4 address or a static IP option. This is particularly relevant for budget and mobile broadband plans.
Install VPN Server And Choose A Protocol
Open VPN Server in DSM and review the available protocols. OpenVPN is generally the best starting point because it provides strong encryption, works across Windows, macOS, Linux, Android and iOS, and uses a portable configuration file. It is also easier to manage consistently across different devices.
L2TP/IPSec may suit older operating systems and some built-in mobile VPN settings, but it involves several ports and can be awkward behind certain routers. PPTP should not be used. It is obsolete and has well-known security weaknesses, even if it still appears in older guides or legacy menus.
Select OpenVPN and enable the server. Review the default settings before saving. You can usually choose the VPN subnet, maximum connections, compression behaviour and whether clients can access the server’s local network. Avoid enabling options you do not need; a smaller, clearer configuration is easier to secure.
Choose a VPN subnet that does not overlap with networks used by remote clients. For example, if your home network is 192.168.1.0/24, use a separate VPN range such as 10.8.0.0/24. Overlapping ranges can prevent a laptop or phone from knowing whether traffic belongs to its current network or your NAS.
Configure Ports, DNS And The Router
OpenVPN commonly uses UDP port 1194. In your router’s port-forwarding section, create a rule that sends UDP 1194 from the internet to the Synology NAS’s fixed local IP address. Use UDP unless you have a specific reason to select TCP, as UDP usually provides better VPN performance.
Do not forward DSM ports such as 5000 or 5001 simply to make remote administration easier. A VPN is designed to provide private access without placing the DSM login page openly on the internet. If you need DSM while away, connect to the VPN first and then use its local address.
You need a hostname if your public IP changes. Synology’s DDNS feature can provide an address such as yourname.synology.me, while some Australian routers and third-party DNS providers offer their own dynamic DNS services. Test that the hostname resolves to your current public address before importing the VPN profile.
If your ISP supplies native IPv6, check whether your security rules cover it. A setup that is locked down over IPv4 may still expose services through IPv6 if the NAS firewall is permissive. Many home users can simplify administration by focusing on a properly secured IPv4 VPN, but IPv6 should not be ignored where it is active.
Export And Secure The OpenVPN Profile
In VPN Server, open the OpenVPN settings and use Export configuration. DSM will download a ZIP archive containing the client profile and supporting certificate files. Extract the archive and open the .ovpn file in a plain-text editor.
Replace the profile’s remote address with your DDNS hostname if it contains a local address or an unsuitable value. The line should point to your public hostname and port, for example:
remote yourname.synology.me 1194
Some Synology profiles include a setting that sends all client internet traffic through the home connection. This can be useful on untrusted hotel or airport Wi-Fi, but it can also reduce speed and use your home data allowance. For ordinary NAS access, split tunnelling may be preferable, allowing only home-network traffic through the VPN.
Treat the exported profile as sensitive information. It contains certificate material that helps authenticate the VPN server. Do not email it casually, upload it to a public drive or leave it in an unsecured shared folder. Create separate DSM accounts for each person who needs access, use long unique passwords and remove access promptly when someone no longer requires it.
Connect Devices And Test Securely
Install an OpenVPN-compatible client on each device. On Windows and macOS, the official OpenVPN client is a common choice. On Android and iPhone, OpenVPN Connect can import the profile from Files, cloud storage or a direct transfer. Import the .ovpn file and certificates, then sign in with the permitted Synology account.
Test from outside your home network. Turn off Wi-Fi on a phone and use mobile data, or connect a laptop through a different broadband service. Testing from the same home Wi-Fi can produce a misleading result because some routers do not support NAT loopback.
After connection, try to open the NAS using its local address, such as https://192.168.1.20:5001, or access a permitted shared folder. Check that the VPN client receives an address from the VPN subnet and that it can reach only the resources intended by your settings.
A useful Australian test is to connect before leaving home and then try it from a different network in another suburb or city. Public Wi-Fi at a Brisbane airport terminal, a serviced office in Sydney or a holiday rental on the Gold Coast can behave very differently from a home NBN connection. Confirm that DNS, file transfers and disconnections work before relying on the setup for an important trip.
Harden The NAS And Maintain The Tunnel
Enable the Synology firewall and allow traffic only from the VPN subnet and trusted local networks where practical. Keep DSM, VPN Server and router firmware updated. Disable unused services, review shared-folder permissions and turn off guest access. A VPN does not compensate for weak account security or overly broad NAS permissions.
Use a separate account for remote access rather than your main administrator account. Limit users to the folders and applications they need. If your DSM version and chosen workflow support multi-factor authentication for the relevant services, enable it, while remembering that VPN authentication and DSM authentication are separate parts of the security design.
Monitor connection logs in VPN Server and DSM. Unexpected repeated login attempts, unfamiliar users or sudden traffic increases deserve investigation. A VPN can protect traffic between a device and your home network, but it cannot protect a compromised laptop, infected phone or stolen credential.
The main options can be compared as follows:
| Option | Strengths | Limitations | Suitable use |
|---|---|---|---|
| OpenVPN | Strong security, broad device support, portable profile | Requires a client app and profile management | Most home and small-business users |
| L2TP/IPSec | Built into many older operating systems | More ports, variable compatibility, less convenient setup | Legacy devices that cannot use OpenVPN |
| PPTP | Simple on old equipment | Obsolete and insecure | Do not use |
| Tailscale or similar mesh VPN | Often works around CGNAT, simple device enrolment | Requires a third-party service and different access model | NBN or mobile connections without inbound access |
| Direct NAS port forwarding | Easy to reach selected services | Increases internet exposure and attack surface | Avoid for DSM and file services where possible |
If CGNAT prevents inbound connections, a mesh VPN such as Tailscale may be more practical than asking an ISP for a public address. It can provide private access without conventional router port forwarding, although it should still be configured with least-privilege access and strong account protection.
Connect your devices through the new VPN, verify access from an external network and keep the exported credentials private. With sensible port forwarding, current firmware and carefully limited accounts, your Synology NAS can remain useful on the road without turning its management interface into a public target.