Remote access to a home NAS

Three ways to reach a home enclosure from outside, what each one exposes, and the configuration that does not depend on a public address.

A remote interface for a photo library accessed from another device

Reaching a home enclosure from outside is what turns storage into a service, and it is also the requirement most often configured in a way that puts the data at risk. Three approaches exist. They differ less in performance than in what they expose to the internet, and the choice is decided by which of those exposures a household is prepared to carry.

The three approaches

Methods compared by what each one requires and what it exposes.
MethodPublic address neededWhat is exposedMaintenance
Port forwardingYesThe appliance's own interface, to all internet trafficHigh; the device's authentication is the only barrier
Vendor relayNoNothing directly; access is carried by the vendor's serviceLow; depends on the vendor
VPN tunnelNo, where outbound relay is supportedNothing; authenticated clients onlyModerate, once set up

Port forwarding performs best and is the hardest to defend. A device interface reachable from the internet is scanned continuously, and the appliance's own login is the only thing between that traffic and the data. It also depends on the public address being available to forward: many connections, particularly mobile and smaller domestic services, place customers behind a shared address, so there is no address of the household's own to forward.

A vendor relay avoids both problems by having the enclosure maintain an outbound connection to a service the household then reaches through. Nothing is forwarded, nothing is exposed directly, and no public address is required. The dependence moves to the vendor's availability and to the security of its relay.

A VPN tunnel terminates on the enclosure or on the router in front of it. It exposes nothing to arbitrary traffic, needs no public address where the router supports an outbound relay mode, and scales further than either alternative: once the tunnel exists, every device on the home network is reachable rather than only the storage. It costs the most effort to establish and the least to live with.

Hardening, whichever method is chosen

  • Multi-factor authentication where the platform offers it. A single password guarding a household's photographs from the whole internet is the weakest link in any of these arrangements.
  • Automatic security updates. An appliance that runs third-party software inherits that software's vulnerabilities, and an unpatched internet-facing device is a matter of when rather than whether.
  • Administrative interfaces kept off the public path. The management console and the file service do not need the same exposure, and separating them reduces what a scanner finds.
  • A separate account for each person and device. Shared credentials cannot be revoked when a device is lost, and they remove the record of who reached what.
  • An off-site copy. Access arrangements protect the data from intrusion; they do nothing about fire, theft or an enclosure fault, which are what the second and third copies exist for.

Where to start

Where to buy a NAS with remote access

This category page links out to a retailer once the final product link is confirmed. Outbound purchase links are treated as affiliate links and are disclosed in the Advertising Disclosure.

Price link pending

Outbound product link pending. Set the "nas-remote-access" key in .workbuddy/tools/product-links.json, then re-run the build, to activate this button.