Skip to Content

NAS & Storage Guides

Is Your NAS Secure? 7 Ways to Lock Down an ASUSTOR NAS (Australia)

Seven practical steps to secure an ASUSTOR NAS: snapshots, offsite backups, VPN, auto blacklisting, new ports, disabling unused services and Wake on WAN.

A NAS is only as secure as its settings. ASUSTOR sets defaults for easy setup, so if your NAS is reachable from the internet, tighten it with seven steps: 1 schedule snapshots, 2 keep an offsite backup, 3 connect through a VPN, 4 turn on auto blacklisting and a whitelist, 5 change the default ports 8000, 8001, 80 and 443, 6 disable services you do not use, such as SSH, and 7 let the NAS sleep with Wake on WAN.

ASUSTOR is clear that there is no guaranteed solution: every step lowers overall risk, and backups with at least one offline copy are the safest protection. ARC IP Networks is a trusted ASUSTOR supplier in Australia: genuine ASUSTOR NAS and accessories at competitive prices, with the full ASUSTOR manufacturer warranty, Australia-wide delivery and trade pricing.

Illustration of a NAS and laptop connected over a VPN while an attacker is blocked
A VPN keeps remote connections private and shuts out attackers (Image: ASUSTOR)

The 7 steps at a glance

StepWhere in ADMProtects against
1. Snapshot CenterSnapshot Center appDeleted, changed or encrypted files
2. Offsite backupCloud Backup Center, MyArchive, Remote Sync, USB backupLoss of the NAS itself
3. VPN connectionsVPN ServerExposing ADM directly to the internet
4. Auto blacklist and whitelistADM DefenderPassword guessing and unknown IP addresses
5. Change default portsSettings, ADM and Web ServerAutomated scans for known ports
6. Disable unused servicesServices (SSH, SFTP, FTP)Attacks on services nobody uses
7. Wake on WAN and sleepHardware, power settingsAttacks while the NAS is idle

Steps from ASUSTOR's "Is your NAS secure?" guide. Menu names are approximate and can vary between ADM versions.

Why NAS security matters

ASUSTOR's security guide opens with the Deadbolt ransomware, which from early 2022 attacked NAS devices from many manufacturers around the world. On an affected NAS almost every file was encrypted and given a ".deadbolt" extension, with a ransom demanded to unlock them. ASUSTOR notes there is no guarantee criminals will unlock files after payment.

What ASUSTOR wants every owner to know

  • Criminal groups are active online, and fixing software vulnerabilities is a race against time; no internet-exposed software is fully secure.
  • Any device or information exposed on the internet is at risk of attack.
  • A NAS has many safety features, but as a network device it is not infallible. Proper backups, with at least one copy offline and disconnected, are the safest protection.
  • If you need higher security, you must change the matching settings to lower the risk.
  • Using only default values carries a higher risk of attack.

ASUSTOR explains that defaults are chosen for compatibility and an easy first setup. Beginners get a NAS that just works; advanced users can tighten settings to the level of risk they accept. "The more rigorous the setting, the safer it is."

Step 1: schedule snapshots

Snapshot Center takes snapshots of Btrfs and iSCSI volumes. ASUSTOR says it supports up to 256 snapshots of a volume, as often as every five minutes, giving you a restore point if data is damaged or lost. MyArchive drives also support Btrfs with snapshots and version history, which protects against accidental deletions and changes.

Step 2: back up to somewhere else

ASUSTOR lists five backup destinations: public cloud services such as Dropbox, Google Drive and Microsoft OneDrive; a MyArchive hard drive; a local computer; a remote NAS; and external storage. Use at least one that is offsite and one that is offline. Our 3-2-1 backup guide explains how to combine them.

Backup from an ASUSTOR NAS to a laptop
Back up to a local computer (Image: ASUSTOR)
Remote Sync between a laptop and an ASUSTOR NAS
Back up to a remote NAS (Image: ASUSTOR)
External drive connected to an ASUSTOR NAS by USB
Back up to external storage (Image: ASUSTOR)

Step 3: connect through a VPN

Rather than opening ADM to the internet, run the NAS as a VPN server (or connect it to an existing VPN as a client). Remote users, branch offices, partners and travelling staff then connect securely first. ASUSTOR lists PPTP, OpenVPN and L2TP/IPsec on this page (and WireGuard on its remote-work page), plus the ability to view live VPN connections and disconnect suspicious ones. We recommend OpenVPN or WireGuard over the older PPTP.

Step 4: auto blacklist and whitelist

  • Auto blacklisting: if an unknown user fails to log in more than a set number of times within a set period, their IP address is blocked automatically.
  • VPN monitoring: view connections on the VPN server and disconnect anything suspicious straight away.
  • Whitelist: allow only specific IP addresses to reach the NAS and refuse everything else.

For a small business with a static office IP, a whitelist is one of the most effective settings available.

ADM Defender settings screen with trusted list and auto blacklist options
ADM Defender: trusted list and auto blacklist settings (Image: ASUSTOR)

Step 5: change the default ports

ASUSTOR warns that the default ports 8000, 8001, 80 and 443 can easily reveal your NAS, and recommends setting your own random four-digit port numbers for ADM and the web server. It will not stop a determined attacker, but it removes you from the easiest automated scans.

Step 6: disable services you do not use

If you do not need SSH and SFTP, turn them off and enable them only when required. ASUSTOR notes that SFTP is needed for EZ-Connect, while most customers rarely need SSH. If remote use is needed, open only the ports you need, whitelist the devices that should connect and deny connections from unknown devices.

ADM settings screen for changing the system HTTP and HTTPS ports
Change the default HTTP and HTTPS ports (Image: ASUSTOR)
ADM services screen with the SSH service option
Turn off SSH when you do not need it (Image: ASUSTOR)

Step 7: let the NAS sleep, wake it on demand

ASUSTOR supports System Sleep Mode (S3) and Wake on WAN. When you do not need the NAS, for example late at night, put it into hibernation. ASUSTOR says its instant wake-up can bring the NAS out of hibernation in 1.5 seconds, so you can wake it remotely when needed and keep it out of reach the rest of the time. See our energy-saving guide for schedules.

Phones waking an ASUSTOR NAS by WOW and WOL, and a NAS in S3 sleep
Wake on WAN and S3 sleep: off when idle, ready in seconds (Image: ASUSTOR)

More settings ASUSTOR recommends

  • Passwords: ASUSTOR's security reminder asks owners to change their password, use a strong one and change the default HTTP and HTTPS ports.
  • TLS version: ADM shows the minimum TLS version for HTTPS connections; browsers that do not meet it cannot connect. ASUSTOR has dropped TLS 1.0 for security reasons.
  • Post-quantum TLS: ASUSTOR says ADM 5.1 and later automatically enable PQC hybrid TLS (X25519 + ML-KEM 768) through TLS 1.3 for browsers that support it, to guard against "harvest now, decrypt later" attacks.
  • 2-Step Verification: ASUSTOR lists it in ADM and EZ Sync; turn it on for every administrator.
  • UPS: an unexpected power cut can corrupt data. ASUSTOR's FAQ explains connecting a UPS by USB and setting it under External Devices > UPS.
  • Updates: keep ADM and apps current; ASUSTOR says each update strengthens defences.

The Australian angle

The ACSC's Essential Eight includes patching applications and operating systems, multi-factor authentication, restricting administrative privileges and regular backups. The steps above cover each of these on your NAS. (General reference only; check the ACSC's current guidance.)

Security features across our ASUSTOR range

Swipe the table sideways to compare all models →

ModelSnapshotsMyArchiveWake on LAN / WANNetwork
AS1204TBtrfs snapshotsNot listedYes2.5GbE
AS3304T v2Snapshot CenterYesYes2.5GbE
AS5404TSnapshot CenterYesYesDual 2.5GbE
AS6704T v2Snapshot CenterYesYesDual 5GbE
AS6706T v2Snapshot CenterYesYesDual 5GbE
AS6804TSnapshot CenterYesYesDual 10GbE + Dual 5GbE

Source: ASUSTOR specifications and product overview pages. ADM Defender, firewall, VPN and 2-Step Verification are listed across these models.

Build it with ARC IP Networks

ARC IP Networks is a trusted ASUSTOR supplier in Australia. We supply genuine ASUSTOR NAS, spare drives for offline backups, NAS and Seagate drive bundles and UPS units, with trade and project pricing for IT providers who harden NAS for clients.

WhoWhat we suggestWhy
Home user, remote photo accessAS1204TBtrfs snapshots, Wake on WAN, 2.5GbE
Home office with offline backupsAS3304T v2MyArchive, hot-swap bays
Small business, remote staffAS5404T with IronWolf 8 TBSnapshot Center, VPN, dual 2.5GbE
Office of 10 to 25AS6704T v2 with 10 TB drivesRAID 6, dual 5GbE, MyArchive
Business with heavier workloadsAS6804TECC DDR5, dual 10GbE

Protect the NAS from power cuts with a UPS from our PowerShield range; our best UPS for a NAS guide explains USB shutdown. Call 1300 100 440 for help.

Shop genuine ASUSTOR NAS

Genuine ASUSTOR with the full 3-year manufacturer warranty. Current Australian pricing (inc. GST) is on each product page.

Drivestor 4 Gen2 AS1204T

Btrfs snapshots, Wake on WAN, 2.5GbE

View AS1204T →

AS5404T

Snapshot Center, dual 2.5GbE, 4 M.2

View AS5404T →

Common questions

Straight answers from the ARC IP Networks team. Last reviewed October 2026.

Defaults are chosen for compatibility and easy setup, and ASUSTOR warns that using only default values carries a higher risk of attack. If the NAS is reachable from the internet, tighten the settings: VPN, auto blacklisting, new ports, unused services off and snapshots on.

ASUSTOR recommends changing the default ports 8000, 8001, 80 and 443 for ADM and the web server to your own random four-digit port numbers.

Yes, unless you need it. ASUSTOR says most customers rarely need SSH, and recommends disabling SSH and SFTP when not required. Note that SFTP is needed for EZ-Connect.

Auto blacklisting blocks an IP address automatically if it fails to log in more than a set number of times within a set period. Combined with a whitelist of trusted addresses, it stops most password-guessing attacks.

Yes. With the NAS as a VPN server, users connect to the VPN first and ADM is not exposed directly. ASUSTOR lists PPTP, OpenVPN and L2TP/IPsec, and WireGuard on its remote-work page; we recommend OpenVPN or WireGuard.

ASUSTOR describes Deadbolt as ransomware that from early 2022 attacked NAS devices from many manufacturers, encrypting almost all files and adding a .deadbolt extension. Updates, hardened settings and offline backups are the best protection.

No. ASUSTOR states there is no guaranteed solution and that no internet-exposed software is fully secure. Each step lowers the overall risk, and backups with at least one offline copy remain the safest protection.

ARC IP Networks is a trusted ASUSTOR supplier in Australia with genuine ASUSTOR NAS, competitive prices, the full manufacturer warranty and Australia-wide delivery. Call 1300 100 440 for trade and project pricing.

Want your NAS hardened properly?

Tell us how your NAS is accessed today. ARC IP Networks will recommend the ASUSTOR NAS, backup drives and UPS, with trade and project pricing.

NAS Ransomware Protection: Prevent, Resist and Recover With ASUSTOR (Australia)
How an ASUSTOR NAS defends against ransomware: Wake on LAN/WAN, ADM Defender, Linux-based ADM, snapshots and offline MyArchive backups, plus what to do if you are hit.