How can I set up a VPN to access my NAS outside my network? :(

I haven’t been able to set up a VPN to connect to my NAS from a remote location.

My ISP doesn’t allow my modem/router to change its LAN settings to bridge mode, so my current set up looks something like this:

Is there a way I can work this out?

Have you tried Tailscale? There’s a package in the Package Center. Create a free account and install the client on your phone and/or computer.

https://www.youtube.com/watch?v=nzBQTJ2isOI

or

QuickConnect is no-brainer IF you only use the Synology apps that it allows you to connect to. For instance, my understanding is that you cannot access Plex using quickconnect because it’s not on their allowed app list.

Using Tailscale, you can access everything on the NAS.

Don’t know whether this is just on my system or if it apples more widely, but I have 1G internet which usually gives me 750Mbps down and 1G up. If I connect Tailscale, the speed is throttled down to 35Mbps and 50 up, just for connecting to their system. I’m probably doing something wrong and would love to hear what it is in the comments.

If you really can’t do bridge mode, then I don’t think a traditional VPN will work since you’ll have a double NAT situation going on and will need ports forwarded on your router and the ISP device. Maybe something like Tailscale/Wireguard would work. There’s several guides about this.

What router (make/model) do you have?

Does quickconnect not work?

I use Raspberry Pi, with WireGuard and PiHole on it.

Use zerotier it’s freaking awesome let me know if you need help.

I’m a huge fan of https://tailscale.com/kb/1131/synology/#enabling-synology-outbound-connections

I use a TP-Link router and it has a VPN function. You just have to set up a username and password. The only trick is that sometimes my IP address changes because I do not have a static IP for my gateway, but I can always look it up using my ISP app…
Had to put my ISP gateway modem into bridge mode and use my own equipment for the VPN function. Traditional ISP equipment does not allow VPNs.
If your ISP doesn’t allow it, it sounds like that tail scale thing might do the job!

I run OpenVPN on the NAS and it works fine behind my router. You have to open the appropriate ports and forward, but there are videos on the web, if you have not done it before.

Yes! It worked perfectly!

Tailscale works like a charm

Thank you! I will look into it.

Thanks for reaching out, Ben!

It’s an Arris TG2482, NAT settings (all LAN settings, actually) are greyed out. https://picbun.com/p/Ysopavqo

to build on this, are you able to purchase and use your own modem?

i have spectrum and i bought my own modem and use my own router.

i use a fortigate FWF-61E that has built in VPN functionality (plus IPS, antivirus, DNS and web filtering etc) but the SSL-VPN does not require the expensive subscriptions. if you want firmware updates you can pay ~$100 US a year for just firmware updates

It does, but I need to map the drive to work directly on some files.

Came here for this. Except I have a tiny wireless travel router running wire guard.

Sure thing. Quick connect is not a vpn. It uses dynamic dns and your data is exposed to the internet. If someone learns your password, they can access your Synology box. Also there have been exploits for Synology and QNAP to access devices using their respective login services. The general consensus is to disable quick connect due to the security risks.

Tailscale creates a secure VPN (virtual private network) tunnel between your device and your Synology device. Once set up, you will be able to access your Synology as if you were on the local network. It’s pretty seamless.