Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Updated links in the proper manner.

The Firewall in SoftNAS helps to control the incoming and outgoing network traffic in VPN.

As of version 5.0, all unnecessary ports for a typical SoftNAS deployment are closed, in order to ensure your security. However, this means that if you are deploying SoftNAS to handle various file protocols, you may need to configure some ports to ensure success. 

To reach the SoftNAS Firewall, expand Settings from the Storage Administration Pane, and select Firewall.

Note
If enabling the firewall, be sure to open up the appropriate set of ports for SSH, HTTP. HTTPS, NFS/bind, iSCSI, CIFS, etc.

To reach the SoftNAS Firewall, expand Settings from the Administration Pane, and select Firewall.

Image Removed

The Firewall wizard will be displayed and you will be able to perform various administrative actions.

Image Removed


Image Added

Configuring the SoftNAS Firewall

As stated, the current SoftNAS Firewall is pre-configured, and set to restrict any ports that are deemed unnecessary to a standard deployment.

This means that only ports and protocols commonly used are configured, including such ports as NFS, CIFS/Samba, rpc-bind, and mountd (iSCSI) are configured to start.  The screenshot on the right is where you can see the ports currently configured by default.Image Removedconfigured to start.

Info

Ports configured to start include:

  • NFS
  • CIFS/SAMBA
  • rpc-bind
  • mountd (iSCSI)


Image Added

Deleting a Service or Port from the SoftNAS Firewall

In order to remove a service or port, simply select the service, and hit the button below stating 'click the Delete Selected Rules'Rules button. 

Note
Buurst does not recommend removing default services without good reason. Please consult Buurst Support if you are unsure of which ports or services you require for your deployment.


Image RemovedImage Added

Adding

a Service or Port to the SoftNAS Firewall

In order to add a service or port, select either Add allowed port or Add allowed service. 

Image Removed

For

Allowed Service

  •  For this example, you will note that we have
nfs
  • NFS as a default service in the current configuration.
This
  •  This refers
to NFSv4
  • to NFSv4 only, as this is the most
common
  • commonly used version
used
  • at the moment.
Let
  •  Let's assume
you are configuring
  • we need to configure SoftNAS to connect with a legacy application that uses
nfs3. Click Add Allowed Service, and you will see on the screenshot to right.

Image Removed

  • NFSv3.

Image Added

  • Select the Add allowed service link.  The Add Service screen will display.

Image Added

  •  Select the service to allow (in this example nfs3) from the dropdown.

  •  Once done,
and
  • click
Create
  • the Create button.

Note
Buurst's SoftNAS can allow traffic from a large list of services, as you can see on the right.


Image RemovedImage Added

  •  The service will show in the allowed list. 

Image Removed

Adding a port is a similar process. Click Image Added

Add Allowed Port

and you will see the following within the screenshot on the right.

Image Removed

Enter the port number to allow. Let us assume that we are adding one of the typical ports used to connect UltraFast. (Note that UltraFast is no longer a part of SoftNAS itself, but we can connect SoftNAS to a Buurst Fuusion instance to configure accelerated file transfers.) UltraFast uses port 8888, and would have that port open to both TCP and UDP traffic.  So, in this example we would type in the Single Port field '8888', then in Network Protocol, select UDP from the dropdown. Click Create when the options are configured. For this example you would repeat the process for a TCP port as well. 

There may be any number of ports and services required for your deployment. If you have any questions regarding the firewall configuration for your use case, please contact Buurst Support for assistance.

Image Removed

  •  Select the Add allowed port link. The Add Port screen will display.

  •  Enter either a Single port or a Port range that you would like to allow.

  •  Select the Network protocol from the drop-down menu.

  •  Once done, click the Create button.

Image Added