Guide

Synology NAS remote access with your own name

DSM has everything you need built in: a customisable dynamic DNS client, a Let’s Encrypt client and a reverse proxy. This guide wires them up so https://nas.yourname.uk.app works from anywhere, with only port 443 facing the internet.

Updated · Checked against Synology DSM 7.2–7.4 Knowledge Center · 5 min read

DSM ports
5000 HTTP, 5001 HTTPS
Port to forward
443 (and 80 for Let’s Encrypt)
DDNS menu
Control Panel → External Access → DDNS
Time
About 30 minutes

QuickConnect, VPN or your own name?

  • QuickConnect is Synology’s relay. It works behind CGNAT with no router changes, but traffic may be relayed through Synology’s servers and can be slow, and the address is a Synology one.
  • VPN: DSM’s VPN Server package, or WireGuard on another box, gives full access to every NAS service – SMB shares included – without exposing any of them.
  • Your own name (this guide): the fastest option for Synology Photos, Drive and the DSM web interface from browsers and apps, as long as you have a public IP. Check for CGNAT first.

1. Add uk.app as a custom DDNS provider

DSM lets you add any provider that updates through a URL. In the uk.app dashboard, create a DDNS token for your name first (My names → your name → Dynamic DNS).

  1. Go to Control Panel → External Access → DDNS and click Customize Service Provider.
  2. Service Provider: ukapp. Query URL:
Query URL
https://__USERNAME__:__PASSWORD__@ddns.uk.app/nic/update?hostname=__HOSTNAME__&myip=__MYIP__
  1. Save, then click Add and choose the ukapp provider you just created.
  2. Hostname: home.yourname.uk.app. Username/Email: yourname.uk.app. Password/Key: the DDNS token. Leave External address on Auto.
  3. Click Test Connection, then OK. The status should read Normal.

DSM fills in the placeholders, sends your username and token as HTTP basic authentication and reads the standard good / nochg replies. The uk.app token is 64 hexadecimal characters, so it needs no special encoding in the URL.

Plan B: a scheduled task

If Test Connection reports an authentication problem on your DSM version, use the Task Scheduler instead: Control Panel → Task Scheduler → Create → Scheduled Task → User‑defined script, run as root every 5 minutes, with this script:

curl -fsS -u "yourname.uk.app:YOUR_DDNS_TOKEN" "https://ddns.uk.app/nic/update?hostname=home.yourname.uk.app"

Finally, in the uk.app DNS settings, add a CNAME record nas → home.yourname.uk.app. Any other names you add later can point at the same place.

2. Decide what to forward

DSM listens on 5000 (HTTP) and 5001 (HTTPS), and individual packages add their own ports – Synology Drive’s desktop client uses 6690, for example. The Synology Router Configuration wizard can’t program most UK ISP hubs, so you will set forwards by hand either way.

Rather than opening several ports, we recommend forwarding only 443 (and 80 for certificate renewals) to the NAS and using DSM’s reverse proxy to reach each service by name. Router steps: BT, Virgin Media, Sky, TP‑Link.

Watch out

Don’t forward SMB (445), AFP, SSH (22) or the DSM ports straight to the internet. Use a VPN for file shares and administration.

3. Get a Let’s Encrypt certificate

  1. Go to Control Panel → Security → Certificate and click Add.
  2. Choose Add a new certificate, then Get a certificate from Let’s Encrypt. Tick Set as default certificate if this NAS has no other.
  3. Domain name: nas.yourname.uk.app. Email: your address. Add other names you plan to use (such as photos.yourname.uk.app) under Subject Alternative Name.
  4. Click Done. DSM proves control over port 80, so that forward must be in place. It renews automatically before expiry.
  5. Click Settings on the same page and assign the certificate to DSM and to each reverse‑proxy name.

Without port 80

If you’d rather keep port 80 closed, get a wildcard certificate with DNS‑01 on another machine (see the HTTPS guide) and upload it with Add → Import certificate. acme.sh also has a synology_dsm deploy hook that uploads renewed certificates for you.

4. Use the built‑in reverse proxy

In DSM 7 the reverse proxy is under Control Panel → Login Portal → Advanced → Reverse Proxy. Create one rule per name:

FieldDSM web interfaceA Docker app (example)
Source protocol / hostname / portHTTPS · nas.yourname.uk.app · 443HTTPS · films.yourname.uk.app · 443
Destination protocol / hostname / portHTTP · localhost · 5000HTTP · localhost · 8096
Custom Header—Create → WebSocket (adds the two upgrade headers)

Also under Login Portal → DSM, tick Automatically redirect HTTP connection to HTTPS for DSM desktop.

5. Lock it down

  • Turn on two‑factor authentication for every administrator: Personal → Security → Sign‑in Method in the account menu, or enforce it for everyone under Control Panel → Security → Account.
  • Enable Auto Block under Control Panel → Security → Protection, for example 10 attempts in 5 minutes.
  • Disable the built‑in admin account and use a named administrator.
  • Keep DSM and packages on automatic updates, and run Security Advisor after making changes.
  • Consider limiting DSM itself to your LAN and VPN using the firewall under Control Panel → Security → Firewall, and publish only the apps you need.

6. Check it from outside

  1. Does the name point home? Look up nas.yourname.uk.app with the DNS lookup and compare the A record with the address on ip.uk.app. After a change, the propagation checker shows which resolvers still have the old one.
  2. Is the port open from the internet? Run the open port checker against port 443, port 80. “Open” means your router forwards it and something answers. “Closed” or “timed out” means the forward, the device’s own firewall or CGNAT is in the way.
  3. Is the certificate right? The SSL checker shows whether the certificate covers the exact name, who issued it and when it expires.
  4. Test from outside for real. Turn Wi‑Fi off on your phone and open the address over mobile data. Testing from inside your own network can give misleading results.

If it doesn’t work

  • DDNS status “Failed” – check the username is your full name (yourname.uk.app) and the password is the DDNS token, not your account password. Try Plan B above.
  • Let’s Encrypt fails – port 80 isn’t reaching the NAS. Test it with the port checker. Behind double NAT both routers need the forward.
  • Name loads the wrong page – the reverse proxy hostname must match exactly what you type, and the certificate must be assigned to it under Settings.

A name for your next idea

Give your website, home server or next project a memorable address: yourname.uk.app. Choose your name and check availability before registering.

Find your name

Questions people ask

Can I keep QuickConnect as well?

Yes. QuickConnect and your own name can run side by side. Apps will use whichever connects.

Why not forward 5001 directly?

It works, but it exposes the whole DSM login on an unusual port and you would need to type :5001 everywhere. The reverse proxy on 443 lets you publish only what you choose, by name.

Does the Synology DDNS client support IPv6?

DSM can report an IPv6 address for providers that accept it. For uk.app, sending your NAS’s IPv6 address in myip creates an AAAA record; make sure the router’s IPv6 firewall allows the ports before you publish one.

Is synology.me still available?

Yes, Synology’s own DDNS names still work and support wildcard certificates. Your own name is useful if you want something memorable, or to use the same name for services that are not on the NAS.

Sources and further reading

We check each guide against the vendor’s own documentation and support forums. If something has changed on your firmware, tell us.

Partners