VPN on router or Synology NAS?

Todd Schmidt

Getting the hang of it
May 17, 2019
119
50
Massachusetts
So finally ditched the Apple AirPort Extreme after 5 years of service. Went with the netgeat orbi, which I discovered supports OpenVPN. So should I switch from running it on my NAS to the router or leave as is? Wondering which would be more secure.
 
Wondering which would be more secure.
Assuming OpenVPN can be trusted your question should be more about risk management: If a host or a device is compromised what is my exposure risk? What do I stand to lose? Additionally, do I have the knowledge or tools to determine that my equipment has been breached?

Out of the gate, Synology wins over Netgear because I trust its OS compared to Netgear's firmware. However, I personally have issues with a NAS at the edge of the open internet being a gatekeeper. So, without additional inputs, I would go with Netgear to minimize the risk of losing the NAS.
 
So finally ditched the Apple AirPort Extreme after 5 years of service. Went with the netgeat orbi, which I discovered supports OpenVPN. So should I switch from running it on my NAS to the router or leave as is? Wondering which would be more secure.
No question, your network would be more secure by letting the router/gateway control VPN.
 
I go with the router. One less port to open on the router to get the NAs to work.
 
With ^^, but I want to add another important reason: if your NAS gets breached, not only can people hop-in to your network, but also steal valuables from your NAS (pictures from your doggo, bank statements, expense reports, tax income, ... ). In my network, my NAS is in the inner-intranet where nobody can enter, not from guest wifi, not from outside. Better be safe than sorry: openVPN at the edge of your network, not inside your network.

I once reworked a dual site Synology NAS with synchronisation, then the idea was to have OpenVPN connect-wise synchronise, but even that is not a requirement as you could easily construct a point2point ssh tunnel for example.

Good luck!
CC
 
  • Like
Reactions: SouthernYankee
Sounds like the consensus is to use the router. Guess I need to figure that out. Anyone know how to setup a static ip and DDNS on the netgear with xfinity internet? That seems to be the only way it‘ll let me do it.
 
I'd be surprised if it required a static IP address (on the WAN side) ... the whole purpose if DDNS is to keep up with dynamic IP addresses.

I don't have an Orbi to use to vet these videos, but they might be helpful:
PreviewPreview3:14Netgear Orbi - How to Setup Dynamic DNS (DDNS) Tutorial
PreviewPreview6:35Netgear Orbi - How to Setup OpenVPN Tutorial
Thanks. It didn’t require the static ip, just the DDNS. In process of figuring it out. Thanks for the videos. Watching them now.
 
  • Like
Reactions: aristobrat
interesting i'll start scanning my logs more closely but i've not had stability issue with that package on a disk station that I have in the wild still running it.
Yeah, mine would randomly drop the connection. And I’d have to disconnect and reconnect a couple times before it would work. the disk station was behind a Comcast router if that helps.