QuickConnect, VPN or your own name?
- QuickConnect is Synology’s relay. It works behind CGNAT with no router changes, but traffic may be relayed through Synology’s servers and can be slow, and the address is a Synology one.
- VPN: DSM’s VPN Server package, or WireGuard on another box, gives full access to every NAS service – SMB shares included – without exposing any of them.
- Your own name (this guide): the fastest option for Synology Photos, Drive and the DSM web interface from browsers and apps, as long as you have a public IP. Check for CGNAT first.
1. Add uk.app as a custom DDNS provider
DSM lets you add any provider that updates through a URL. In the uk.app dashboard, create a DDNS token for your name first (My names → your name → Dynamic DNS).
- Go to Control Panel → External Access → DDNS and click Customize Service Provider.
- Service Provider:
ukapp. Query URL:
https://__USERNAME__:__PASSWORD__@ddns.uk.app/nic/update?hostname=__HOSTNAME__&myip=__MYIP__- Save, then click Add and choose the
ukappprovider you just created. - Hostname:
home.yourname.uk.app. Username/Email:yourname.uk.app. Password/Key: the DDNS token. Leave External address on Auto. - Click Test Connection, then OK. The status should read Normal.
DSM fills in the placeholders, sends your username and token as HTTP basic authentication and reads the standard good / nochg replies. The uk.app token is 64 hexadecimal characters, so it needs no special encoding in the URL.
Plan B: a scheduled task
If Test Connection reports an authentication problem on your DSM version, use the Task Scheduler instead: Control Panel → Task Scheduler → Create → Scheduled Task → User‑defined script, run as root every 5 minutes, with this script:
curl -fsS -u "yourname.uk.app:YOUR_DDNS_TOKEN" "https://ddns.uk.app/nic/update?hostname=home.yourname.uk.app"Finally, in the uk.app DNS settings, add a CNAME record nas → home.yourname.uk.app. Any other names you add later can point at the same place.
2. Decide what to forward
DSM listens on 5000 (HTTP) and 5001 (HTTPS), and individual packages add their own ports – Synology Drive’s desktop client uses 6690, for example. The Synology Router Configuration wizard can’t program most UK ISP hubs, so you will set forwards by hand either way.
Rather than opening several ports, we recommend forwarding only 443 (and 80 for certificate renewals) to the NAS and using DSM’s reverse proxy to reach each service by name. Router steps: BT, Virgin Media, Sky, TP‑Link.
Watch out
Don’t forward SMB (445), AFP, SSH (22) or the DSM ports straight to the internet. Use a VPN for file shares and administration.
3. Get a Let’s Encrypt certificate
- Go to Control Panel → Security → Certificate and click Add.
- Choose Add a new certificate, then Get a certificate from Let’s Encrypt. Tick Set as default certificate if this NAS has no other.
- Domain name:
nas.yourname.uk.app. Email: your address. Add other names you plan to use (such asphotos.yourname.uk.app) under Subject Alternative Name. - Click Done. DSM proves control over port 80, so that forward must be in place. It renews automatically before expiry.
- Click Settings on the same page and assign the certificate to DSM and to each reverse‑proxy name.
Without port 80
If you’d rather keep port 80 closed, get a wildcard certificate with DNS‑01 on another machine (see the HTTPS guide) and upload it with Add → Import certificate. acme.sh also has a synology_dsm deploy hook that uploads renewed certificates for you.
4. Use the built‑in reverse proxy
In DSM 7 the reverse proxy is under Control Panel → Login Portal → Advanced → Reverse Proxy. Create one rule per name:
| Field | DSM web interface | A Docker app (example) |
|---|---|---|
| Source protocol / hostname / port | HTTPS · nas.yourname.uk.app · 443 | HTTPS · films.yourname.uk.app · 443 |
| Destination protocol / hostname / port | HTTP · localhost · 5000 | HTTP · localhost · 8096 |
| Custom Header | — | Create → WebSocket (adds the two upgrade headers) |
Also under Login Portal → DSM, tick Automatically redirect HTTP connection to HTTPS for DSM desktop.
5. Lock it down
- Turn on two‑factor authentication for every administrator: Personal → Security → Sign‑in Method in the account menu, or enforce it for everyone under Control Panel → Security → Account.
- Enable Auto Block under Control Panel → Security → Protection, for example 10 attempts in 5 minutes.
- Disable the built‑in
adminaccount and use a named administrator. - Keep DSM and packages on automatic updates, and run Security Advisor after making changes.
- Consider limiting DSM itself to your LAN and VPN using the firewall under Control Panel → Security → Firewall, and publish only the apps you need.
6. Check it from outside
- Does the name point home? Look up
nas.yourname.uk.appwith the DNS lookup and compare the A record with the address on ip.uk.app. After a change, the propagation checker shows which resolvers still have the old one. - Is the port open from the internet? Run the open port checker against port 443, port 80. “Open” means your router forwards it and something answers. “Closed” or “timed out” means the forward, the device’s own firewall or CGNAT is in the way.
- Is the certificate right? The SSL checker shows whether the certificate covers the exact name, who issued it and when it expires.
- Test from outside for real. Turn Wi‑Fi off on your phone and open the address over mobile data. Testing from inside your own network can give misleading results.
If it doesn’t work
- DDNS status “Failed” – check the username is your full name (
yourname.uk.app) and the password is the DDNS token, not your account password. Try Plan B above. - Let’s Encrypt fails – port 80 isn’t reaching the NAS. Test it with the port checker. Behind double NAT both routers need the forward.
- Name loads the wrong page – the reverse proxy hostname must match exactly what you type, and the certificate must be assigned to it under Settings.