{"id":3170,"date":"2026-01-09T00:37:24","date_gmt":"2026-01-09T00:37:24","guid":{"rendered":"https:\/\/help.peacedoorball.blog\/ca\/?p=3170"},"modified":"2026-01-09T00:37:24","modified_gmt":"2026-01-09T00:37:24","slug":"comment-restreindre-lacces-a-votre-nas-synology-depuis-des-pays-indesirables","status":"publish","type":"post","link":"https:\/\/help.peacedoorball.blog\/ca\/comment-restreindre-lacces-a-votre-nas-synology-depuis-des-pays-indesirables\/","title":{"rendered":"Comment restreindre l&rsquo;acc\u00e8s \u00e0 votre NAS Synology depuis des pays ind\u00e9sirables"},"content":{"rendered":"<p>Cet article explique comment bloquer les tentatives de connexion ind\u00e9sirables sur votre NAS Synology, en particulier celles provenant de pays depuis lesquels vous \u00eates certain de ne pas vouloir acc\u00e9der. Il s&rsquo;agit d&rsquo;attaques par force brute (car, bien s\u00fbr, les pirates informatiques adorent exploiter les failles de s\u00e9curit\u00e9), et m\u00eame apr\u00e8s avoir appliqu\u00e9 les mesures de s\u00e9curit\u00e9 habituelles (activation du blocage automatique, protection des comptes, etc.), cela ne suffit parfois pas. La solution suivante consiste donc \u00e0 bloquer des pays entiers dans le pare-feu. Cela para\u00eet radical ? Peut-\u00eatre. Mais si vous \u00eates constamment la cible de tentatives de connexion provenant de certaines r\u00e9gions, cette m\u00e9thode vaut la peine d&rsquo;\u00eatre essay\u00e9e.<\/p>\n<p>Bloquer des pays entiers n&rsquo;est pas infaillible (cela pourrait exclure les utilisateurs l\u00e9gitimes qui voyagent ou se connectent via VPN \u00e0 ces r\u00e9gions), mais c&rsquo;est un bon moyen de limiter le trafic malveillant. De plus, c&rsquo;est \u00e9tonnamment simple une fois qu&rsquo;on a compris le principe, surtout si vous utilisez d\u00e9j\u00e0 le pare-feu int\u00e9gr\u00e9 de DSM. Attention : selon votre configuration, vous devrez peut-\u00eatre ajuster certaines r\u00e8gles si votre configuration IP ou votre utilisation d&rsquo;un VPN devient plus complexe. Voici donc la proc\u00e9dure \u00e9tape par \u00e9tape pour bloquer l&rsquo;acc\u00e8s depuis certains pays sur votre NAS Synology.<\/p>\n<h2>Comment emp\u00eacher l&rsquo;acc\u00e8s \u00e0 un NAS Synology depuis d&rsquo;autres pays \u00e0 l&rsquo;aide du pare-feu DSM<\/h2>\n<h3>V\u00e9rifiez d&rsquo;abord vos param\u00e8tres r\u00e9seau.<\/h3>\n<p>Avant de modifier les r\u00e8gles du pare-feu, assurez-vous que les informations de votre r\u00e9seau sont correctes. Cela vous \u00e9vitera de vous bloquer l&rsquo;acc\u00e8s ou d&rsquo;autoriser accidentellement un acc\u00e8s non autoris\u00e9. Pour ce faire :<\/p>\n<ul>\n<li><strong>Ouvrez<\/strong> le <strong>Panneau de configuration<\/strong> dans DSM, puis cliquez sur <strong>R\u00e9seau<\/strong>.<\/li>\n<li><strong>S\u00e9lectionnez<\/strong> l&rsquo; onglet <strong>Interface r\u00e9seau<\/strong>, puis <strong>d\u00e9veloppez<\/strong> vos param\u00e8tres LAN.<\/li>\n<li>Notez votre plage d&rsquo;adresses IP (comme<code>192.168.1.x) and subnet mask (possibly <code>255.255.255.0<\/code>).That info is key for allowing local access later.<\/code><\/li>\n<p><code> <\/code><\/ul>\n<p><code> <\/p>\n<h3>Set Up DSM Firewall Rules To Block Countries<\/h3>\n<p>This part is kinda the core of it. You need three rules: one for local network access, one to allow your country, and one to block everything else. Sounds simple in theory, but the devil is in the details. Here\u2019s what to do:<\/p>\n<ol>\n<li><strong>Enable Firewall<\/strong>: Head into <strong>Control Panel &gt; Security &gt; Firewall<\/strong>. Check the box for <strong>Enable Firewall<\/strong> and hit <strong>Edit Rules<\/strong>. This is what triggers the filtering.<\/li>\n<li><strong>Create the first rule (Allow LAN)<\/strong>: Click <strong>Create<\/strong>. Set the action to <strong>Allow<\/strong>, and choose <strong>Specific IP<\/strong>. Under <strong>Source IP<\/strong>, pick <strong>Subnet<\/strong> and input your local network info (e.g., <code>192.168.1.0<\/code>) and subnet mask (<code>255.255.255.0<\/code>).This makes sure your local devices can continue to access DSM without a hitch.<\/li>\n<li><strong>Create the second rule (Allow your country)<\/strong>: Again, <strong>Create<\/strong>. Action: <strong>Allow<\/strong>. This time, pick <strong>Location<\/strong> &amp; type your country\u2019s name or select it from the list. This way, legitimate users from your area won\u2019t get blocked.<\/li>\n<li><strong>Create the third rule (Deny other countries)<\/strong>: Final create\u2014action: <strong>Deny<\/strong>. Leave all ports and source IP options as the defaults (all sources), so it blocks everything else. No need to get fancy here\u2014just a blanket deny.<\/li>\n<li><strong>(Optional) Add static IP rules<\/strong>: If you have a static IP from your ISP, make a rule for that IP, and move it above the deny rule. Otherwise, it might get caught in the crossfire.<\/li>\n<\/ol>\n<p>Important: pay attention to rule order. The firewall processes rules top-down, so your LAN and your country need to be at the top, with the deny rule at the bottom. Otherwise, you risk locking yourself out or letting unwanted traffic slip in.<\/p>\n<p>Finally, click <strong>OK<\/strong> and then <strong>Apply<\/strong>. Exit, and your settings are live. Keep an eye on your NAS logs for any unexpected access\u2014sometimes, legit users or VPNs might get caught if they\u2019re outside your allowed regions.<\/p>\n<p>Doing all this can help cut down brute force attempts, especially if you notice weird spikes from certain countries. Sure, it\u2019s not a magic fix, but it\u2019s one more layer of protection that doesn\u2019t require complex VPN setup or extra hardware. Just remember: on some setups, this might block legit remote workers or travelers, so maybe disable temporarily if you notice issues.<\/p>\n<h2>Summary<\/h2>\n<ul>\n<li>Checked network IP range and subnet mask<\/li>\n<li>Enabled DSM firewall and created rules to allow LAN and your country<\/li>\n<li>Added a blanket deny rule for everything else<\/li>\n<li>Optionally added static IP exception<\/li>\n<\/ul>\n<h2>Wrap-up<\/h2>\n<p>This approach might seem a bit harsh, but for some setups, it\u2019s the easiest way to shut down brute force onslaughts from entire regions. Make sure to test your access after setting everything up\u2014especially from different locations or using VPNs\u2014to confirm legitimate users aren\u2019t getting blocked. Sometimes, this requires a bit of tweaking, but for most, it\u2019s a solid step towards a more secure NAS. Fingers crossed this helps someone avoid sleepless nights over unwanted login attempts.<\/p>\n<p> <\/code><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cet article explique comment bloquer les tentatives de connexion ind\u00e9sirables sur votre NAS Synology, en particulier celles provenant de pays depuis lesquels vous \u00eates certain<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3170","post","type-post","status-publish","format-standard","hentry","category-aide"],"_links":{"self":[{"href":"https:\/\/help.peacedoorball.blog\/ca\/wp-json\/wp\/v2\/posts\/3170","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/help.peacedoorball.blog\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/help.peacedoorball.blog\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/help.peacedoorball.blog\/ca\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/help.peacedoorball.blog\/ca\/wp-json\/wp\/v2\/comments?post=3170"}],"version-history":[{"count":0,"href":"https:\/\/help.peacedoorball.blog\/ca\/wp-json\/wp\/v2\/posts\/3170\/revisions"}],"wp:attachment":[{"href":"https:\/\/help.peacedoorball.blog\/ca\/wp-json\/wp\/v2\/media?parent=3170"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/help.peacedoorball.blog\/ca\/wp-json\/wp\/v2\/categories?post=3170"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/help.peacedoorball.blog\/ca\/wp-json\/wp\/v2\/tags?post=3170"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}