How to Secure Your Unraid Server 🖥️ Unraid Security Best Practices

Поделиться
HTML-код
  • Опубликовано: 16 окт 2024

Комментарии • 58

  • @BeardedTechGuy
    @BeardedTechGuy  3 года назад +8

    What other steps are you taking to secure your Unraid storage server? Let me know below!

    • @topytopy
      @topytopy 2 года назад +2

      Hi TBTG!
      I have been trying to harden the SMB configuration with the following improvements:
      Null passwords are disabled, SMB signing is mandatory, SMB encryption is mandatory, the minimum protocol version for supported is SMB3_11 for all communications and the ntlm auth is configured to be ntlmv2-only. I have not yet found a way to configure this correctly via the web interface as the "Samba extra configuration" field is confusing. If you could create an additional video about this, that would be exceptionally helpful! Thanks.

  • @alice20001
    @alice20001 3 месяца назад +1

    EPIC! This is phenomenal. It's both general good security practices as well as high level hardening that just about every video misses!
    Outstanding!

  • @thebaldfox
    @thebaldfox 3 года назад +7

    Great video, logical and well laid out. I just subbed... would love to see a walk through or a breakdown of reverse proxy, the pros and cons / vulnerabilities in a similar manner, rather than just the usual this is how to install it in docker and add cloudflare :)

    • @BeardedTechGuy
      @BeardedTechGuy  3 года назад +1

      Glad you liked the video and thank you for subscribing!
      I'll keep your suggestion in mind for an upcoming video, thanks for the input!

  • @RagnarRipper
    @RagnarRipper 3 года назад +1

    That was a great video! Watched it just to make sure and I'm pretty proud that I did all the things already :)

  • @arnoldfriend8197
    @arnoldfriend8197 3 года назад +4

    Great video!!

  • @ZombieTechie
    @ZombieTechie 8 месяцев назад +1

    Love the channel name!

  • @jpulley
    @jpulley 3 года назад +3

    Very helpful, subbed!

    • @BeardedTechGuy
      @BeardedTechGuy  3 года назад +1

      Glad you found the video and thank you for subscribing!

  • @cd9954
    @cd9954 9 месяцев назад +1

    Good info thanks. Since you keep that port for Plex open, isn’t that a vulnerability? Do you have docker running? Fail2ban?

  • @gamer1xbox360
    @gamer1xbox360 2 года назад +2

    Great tutorial and well explained, thank you

  • @roberts_irregular_random_rec
    @roberts_irregular_random_rec 3 года назад +2

    At 7:06, hard to understand what you are saying: ". . . for this setting, I recommend setting to yes and ????"
    Nice video - thank you for creating this.

    • @BeardedTechGuy
      @BeardedTechGuy  3 года назад +1

      Oh wow, guess my noise gate caught me there. I recommend "Yes (Hidden)"
      That's the problem with listening to my own videos, my ears fill in gaps I know no matter how many times I listen to it. Thanks for catching that!

  • @daz7748
    @daz7748 3 года назад +1

    Very well explained, thank you!

  • @thenanook
    @thenanook 3 года назад +1

    good info, liked and subscribed

  • @Richardj410
    @Richardj410 2 года назад +1

    Thanks, it's sinking in slowly.

  • @xxxxxxsauron
    @xxxxxxsauron Год назад +1

    thanks. please make a total noob video on everything unraid.. with SMB explained also how to use torrent and prowlarr with openvpn. how to setup plex with hardware transcoding

  • @sidewind131258
    @sidewind131258 Год назад +1

    I was following along and making changes here and there as I thought I needed them, and when I was finished with "Turn on Unraid notifications" I found out that I suddently had explanations folded out everywhere, do you have any idea on where to turn those off ? I run version 6.11.5

    • @BeardedTechGuy
      @BeardedTechGuy  Год назад +1

      In the top right hand corner there should be a little question mark in a circle. If it has a line under it, that means it's enabled / selected witch auto expands all the tips. If you want that off, it should not have a line under it.
      Here is what it looks like when off (top image) and on (bottom image): imgur.com/a/rbFW0EF

  • @DarkwaterV2
    @DarkwaterV2 2 года назад +1

    Thanks a lot!

  • @onestopviewfiles
    @onestopviewfiles 3 года назад +1

    12:12 so are plex ports on 32400 that are port forwarded ok? just don't forward any common ports like port 80?

    • @BeardedTechGuy
      @BeardedTechGuy  3 года назад +1

      So realistically, any port forwarding (including Plex) introduces risk to your network. For me, I "trust" Plex enough to be served traffic from the Internet so I port forward 32400 for it. Port 80 is usually used for HTTP traffic which means it is not encrypted and sent in the clear, so anyone who can see the traffic can see the contents. Because of this, it is recommended to not use and instead use HTTPS over 443 with a certificate to help protect the traffic - IF you need web browser traffic forwarded to a device in your home network. Even though HTTPS is encrypted, anyone can still access the webpage so that server could still be hacked.

    • @onestopviewfiles
      @onestopviewfiles 3 года назад +1

      @@BeardedTechGuy thanks dude, so if I just only have the plex port forwarded, and thats it, then I should be ok?

    • @BeardedTechGuy
      @BeardedTechGuy  3 года назад +1

      If you only have 32400 being forwarded then that would be the only traffic sourced from the Internet that would get forwarded into your home network. At that point, as long as your Plex server isn't vulnerable for any known attacks (always keep it up to date to help protect it), then your risk would be minimal.

  • @johnmarkzimm
    @johnmarkzimm 2 года назад +1

    Do you install anti virus software on your Unraid server... the only one I see is calmav.

    • @BeardedTechGuy
      @BeardedTechGuy  2 года назад

      Great question! That honestly never crossed my mind. Are you asking for the files stored on the shares of Unraid or for the Unraid OS / storage itself?

  • @Calamity_Jack
    @Calamity_Jack 2 года назад

    Do you need SSH if you're using the My Servers feature?

    • @BeardedTechGuy
      @BeardedTechGuy  2 года назад

      My understanding is that you would not need SSH for the My Servers feature, so it should be able to be turned off if you don't want even local (on network) remote access to the server.

    • @Calamity_Jack
      @Calamity_Jack 2 года назад

      @@BeardedTechGuy Thanks for that. I do remotely access my server via my PC (local, on the same intranet) to manage it, so would I need to leave SSH enabled to do that? Or does My Servers bypass all of that and allow me to remotely admin my server via browser on my PC?

    • @BeardedTechGuy
      @BeardedTechGuy  2 года назад

      SSH is used for the CLI access. For GUI either local or through "My Servers" uses HTTPs. If you do not need CLI access to unraid locally you should be able to disable SSH without impact to My Servers.

    • @Calamity_Jack
      @Calamity_Jack 2 года назад +1

      @@BeardedTechGuy Awesome, thx for clarifying!

  • @ajugland
    @ajugland 2 года назад

    Still dont know how my PC always prompt for credentials even though its a public share

    • @BeardedTechGuy
      @BeardedTechGuy  2 года назад

      Hmm that's a weird one. You could check the credential store and see if a account is saved for it. Or if its not too destructive I'd remove the share and readd it to see what happens.

  • @whizadree
    @whizadree 3 года назад +1

    I wouldnt do DMZ

  • @seamydobbsno1
    @seamydobbsno1 3 года назад +1

    Are you bound to the beard for the lifetime of your channel now?

    • @BeardedTechGuy
      @BeardedTechGuy  3 года назад +1

      One does not choose The Beard, The Beard chooses the one.

    • @seamydobbsno1
      @seamydobbsno1 3 года назад +1

      @@BeardedTechGuy My understanding of the truth is that I am talking to the beard 🙌

  • @TechySpeaking
    @TechySpeaking 3 года назад +2

    first

  • @GrandmaHatesTech
    @GrandmaHatesTech 3 года назад +1

    I have a 200 pound dog to make sure nobody accesses my computer Grrrrr

    • @BeardedTechGuy
      @BeardedTechGuy  3 года назад +4

      Not sure why but I just imagined Snoopy sitting on a laptop wearing the typical "hacker gear" lol

  • @Redneckrampage
    @Redneckrampage 3 года назад

    Secure unraid don't don't mention about unraid SSL

  • @activate_filmscore
    @activate_filmscore 2 месяца назад

    🛑🛑🛑That’s not what ppl are clicking this for …. Ppl want volume and pool encryption…. Answer is unfair can’t do it … true nas can🛑🛑🛑

  • @jbrown70579
    @jbrown70579 3 года назад

    Really trying to monetize this video? 10 ads in 15 mins? Seriously? Thumbs down.

    • @BeardedTechGuy
      @BeardedTechGuy  3 года назад +3

      I think I'm getting ripped off! I only put 3 ad breaks in for the 15 minute video and RUclips very rarely uses all of them ¯\_(ツ)_/¯
      imgur.com/a/KmawmsA