Reaching a home enclosure from outside is what turns storage into a service, and it is also the requirement most often configured in a way that puts the data at risk. Three approaches exist. They differ less in performance than in what they expose to the internet, and the choice is decided by which of those exposures a household is prepared to carry.
The three approaches
| Method | Public address needed | What is exposed | Maintenance |
|---|---|---|---|
| Port forwarding | Yes | The appliance's own interface, to all internet traffic | High; the device's authentication is the only barrier |
| Vendor relay | No | Nothing directly; access is carried by the vendor's service | Low; depends on the vendor |
| VPN tunnel | No, where outbound relay is supported | Nothing; authenticated clients only | Moderate, once set up |
Port forwarding performs best and is the hardest to defend. A device interface reachable from the internet is scanned continuously, and the appliance's own login is the only thing between that traffic and the data. It also depends on the public address being available to forward: many connections, particularly mobile and smaller domestic services, place customers behind a shared address, so there is no address of the household's own to forward.
A vendor relay avoids both problems by having the enclosure maintain an outbound connection to a service the household then reaches through. Nothing is forwarded, nothing is exposed directly, and no public address is required. The dependence moves to the vendor's availability and to the security of its relay.
A VPN tunnel terminates on the enclosure or on the router in front of it. It exposes nothing to arbitrary traffic, needs no public address where the router supports an outbound relay mode, and scales further than either alternative: once the tunnel exists, every device on the home network is reachable rather than only the storage. It costs the most effort to establish and the least to live with.
Hardening, whichever method is chosen
- Multi-factor authentication where the platform offers it. A single password guarding a household's photographs from the whole internet is the weakest link in any of these arrangements.
- Automatic security updates. An appliance that runs third-party software inherits that software's vulnerabilities, and an unpatched internet-facing device is a matter of when rather than whether.
- Administrative interfaces kept off the public path. The management console and the file service do not need the same exposure, and separating them reduces what a scanner finds.
- A separate account for each person and device. Shared credentials cannot be revoked when a device is lost, and they remove the record of who reached what.
- An off-site copy. Access arrangements protect the data from intrusion; they do nothing about fire, theft or an enclosure fault, which are what the second and third copies exist for.
Where to start
- What a NAS needs from the network — link rates, switch placement and the access question in context.
- What a NAS actually does — the photo and media features that create the remote-access requirement.
- NAS buying guide — the purchase decisions that come before access is configured.
Where to buy a NAS with remote access
This category page links out to a retailer once the final product link is confirmed. Outbound purchase links are treated as affiliate links and are disclosed in the Advertising Disclosure.
Price link pendingOutbound product link pending. Set the "nas-remote-access" key in .workbuddy/tools/product-links.json, then re-run the build, to activate this button.