User's Manual
Synology DiskStation User's Guide
Based on DSM 3.0
57 Chapter 6: Enhance Internet Security
Prevent Unauthorized Connection with Firewall
The built-in firewall can prevent unauthorized logins, and control which services can be accessed. In addition,
you can choose to allow or deny access to certain network ports from specific IP addresses.
Go to Main Menu > Control Panel > Firewall to create firewall rules.
Note: You can create up to 100 rules for Synology DiskStation.
To create a firewall rule:
1 Click the General, LAN 1, LAN 2 (dual LAN models only), LAN, PPPoE, or Wireless Network tab, depending
on the type of your network connection.
2 Click Create to open the settings window.
3 Choose an option in the Ports section. You can apply the rule to all ports or selected ports using one of the
following options:
All: Choose this option to apply the rule to all ports on Synology DiskStation.
Select from a list of built-in applications: Tick the system services that will be included in the rule.
Custom: Specify the type and protocol of the port, and enter the custom port number.
You can enter up to 15 ports separated with comma, or by specifying a port range.
4 Specify the source IP address in the Source IP section. You can choose to allow or deny access from a
particular source IP using one of the following options:
All: Choose this option to apply the rule to all source IP addresses.
Single host: Choose this option to apply the rule to an IP address.
Subnet: Choose this option to apply the rule to a subnet.
5 Choose Allow or Deny in the Action section to allow or deny the source IP address to access the specified
ports.