How do you enable SSH on a NAS? Feiniu switches on Synology and hooks it, reposting on the 22nd half month, I get scanned every day

last year when the hard drive was in hibernation, I wanted to keep an eye on what the NAS was writing on the drive every minute, but the webpage backend was completely turned upside down, but there was no such feature. Finally, SSH logged in, and after a night of iOS top, they finally caught the qBittorrent that had stolen the drive. I wrote about this troubleshooting process in the of the hard drive sleep—that was my first time actually using SSH. Previously, in my eyes, this switch was 'only for advanced users,' and I was nervous for a whole year.
What is
SSH: the backdoor that the webpage backend can't reach
to give an example, the NAS web management interface is the front desk reception where you can ask anything, but you can only press the buttons it provides; SSH is the door to the kitchen. Once inside, you're facing the entire underlying system of the machine. Feiniu uses Debian, Synology is also Linux infrastructure, and the command line can do everything you can't click on the webpage.
I later looked back at the NAS articles I had written about it, realizing that more than half of the troubleshooting and tinkering couldn't be separated from this door: to check who wakes up the hard drive from sleep, you have to log in and run iOS Top to see every minute of writes; To clear duplicate files from 40,000 photos, you need to install an fdupes deduplication in APT; Sometimes the hard drive doesn't recognize it, so you have to use DMESG to kernel log . These tasks share a common trait—there is no corresponding page in the webpage backend.
so SSH is not a hacking tool; it is another way to log in to NAS. Your usual account and password remain the same, just switch from the browser to enter in a black window. Windows 10 and later systems come with this client. Hold down the Win key and enter "Terminal" or "cmd" to open it, no need to install any software.
Feiniu Enables SSH: A Switch Matter
Feiniu's entrance is shallowly hidden, only two steps away:
log into Feiniu's desktop, click Settings in the lower left corner, go to the Security section, and there's an SSH option. Check "Enable SSH Service"; port default is 22, no need to change it, save. The newer firmware switch is placed in the security page of the settings. For older versions, you can look for the SSH name in the Control Panel's System Settings. The name is the same, and if you can't find it, it means you need to upgrade the firmware.
Then go back to your computer and open the terminal, typing this line:
ssh Your username@192.168.31.20
change the username to your FN ID account, and the IP address to your own NAS address—if you don't know the IP, check the router device list. My NAS is bound to a static IP, 192.168.31.20, so I won't be unable to connect to DHCP one day when I change the number.
the first time, it even throws out a warning saying "Cannot verify the authenticity of the device," asking if you want to continue. This is recording the NAS's fingerprint—just enter yes and press Enter, and it won't ask again. Next, enter the password—note that when entering the password, not a single character appears on the screen. It's not because the keyboard is broken, but you just typed in and press Enter. When you see the command prompt change appearance, you're already inside the NAS.
at this time, the users logging in are still regular users. If you want to install software or view system logs, you have to request permission again:
sudo -i
enter your password once, and the prompt becomes a hash signal, you are rooted. Feiniu runs Debian at the bottom; installing something directly is APT. I installed the duplicate file's FDUPES like this, which takes twenty seconds.
Synology enables SSH: One checkbox on the control panel
my cousin's second-hand Synology has been helped with it. The path is even more straightforward: Control Panel, find "Terminals and SNMP," check "Enable SSH function," port also defaults to 22, and it takes effect after application. The connection command is exactly the same, but the account uses your administrator account. Synology usually defaults to admin.
difference is after entering. Synology doesn't have APT. If you want to install tools not in the package center, either download a statically compiled executable file and run it there, or use Docker to create a container and work around it—I reviewed the duplicate file that installer installation guide I wrote about this comparison. Synology and his team have to take a detour about apt.
but the troubleshooting commands are accepted by both companies, since both are Linux. Sometimes I couldn't recognize that hard drive. I went in for SSH, typed dmesg plus grep, and saw the repeated reset records of the SATA link. That's when I shifted the direction from 'the drive is broken' to 'loose cable,' and swapped out a clip cable for six yuan. sudo -i escalation is also universal.
What can you do after
connects: the Gojo
I use most often.don't have to memorize orders; just search whatever you need and just slip into the dark window and get in. These five items cover 90% of my daily needs:
What
| command | my actual scenario | |
| df -h | check how much space is left on each disk | storage pool alarm that time, first use it to locate which volume is full |
| top | to see who was using CPU or memory, | face recognition running during those days, I confirmed the N100's quad-core consisted of 70% |
| iotop -o | see who is reading and writing hard drives | hanging overnight and catching qBittorrent writing every five minutes session |
| dmesg | grep -i sata | check the underlying logs of the hard drive or not | the night the hard drive disappeared, saw the link reset record locking the SATA line |
| free -h | check memory usage and remaining __ Before HTML106__ | up memory, check how much it actually consumes—don't buy based on your feelings |
one step further, I use SSH with password-free login. When I set up my mom's old Synology for remote backups, I used it: local ssh-keygen generates the key, pushing the public key to the host machine, so from now on, running scripts between the two NAS systems won't require manual password entry. There's a permission pitfall I've encountered before—the home directory and .ssh directory on the other end have 700 values, and the authorized_keys file has to be 600. If permissions are relaxed, the system will ignore the key and silently return for the password. It took me half an evening to realize that I remember the entire process of backup with two NAS devices in different locations.
Three Bottom Lines of Safety: Reposting 22 Weeks, I Was Scanned Every Day
here to teach a lesson. Two years ago, to save trouble, I wanted to connect SSH to my home NAS from outside, so I forwarded port 22 to the public network on the router. Half a month later, when I logged into Synology's security log, I felt a chill down my spine: thousands of login failure records, all from overseas IPs. The accounts I tested were all admin, root, test, and Ubuntu—several times per second. It was purely scripted to run the dictionary.
nothing happened was thanks to the long password and luck. That same day, I deleted the forwarded post, and since then there haven't been a single failed record. Since then, I've set three boundaries for myself, and you copy them too:
bottom line one: SSH ports will never forward to the public network. want to connect from outside, use a VPN or Tailscale networking tools. Once connected, your home network environment will have an SSH internal network address exactly the same as at home. This is the same principle as NAS ransomware that "management page is not exposed"—if attackers can't reach the door, you don't have to race against their dictionary.
bottom line two: switch to high-level ports and don't be too obsessive. online tutorials teach you to change 22 to 18022 or similar high-level ports, which is useful, but only for those scripts that scan the entire segment—targeting attackers targeting you to scan all ports. I don't even bother changing the port of my home intranet, since I can't get out anyway.
Bottom Line 3: Key login is an advanced option, not a mandatory one. keys are harder than passwords, but the process of assigning them involves permission pitfalls, and if you lose the key file or lock your password to log in early, you lock yourself out. For home use, just make sure the first password doesn't expose the public network, the password is at least 16 digits, and you have automatic blocking—Synology has a 'Login Failure Auto Block' option in the Security and Accounts Control Panel. Enable it, and after a few failures, the source IP is locked in a black room. This is just a couple of clicks on the graphical interface, much less hassle than a key. Feiniu's new firmware also includes a similar automatic lock switch in the security settings, so you can easily turn it on whenever you have one.
when to open it and when to avoid it
Not everyone has to drive it. I drive the one at home because I have a lot of work to do; I drove my mom's car to run backup scripts; But if my cousin only uses the NAS to save photos and watch movies, he can never flip this switch for a lifetime without losing anything.
| your situation | should you open a | |
| you need to check logs or install tools not available in the web backend, | open. After use, you can turn them off | |
| and run automatic backup scripts between the two NASs, | enable them, and also enable password-free | |
| purely for storing files, watching videos, and backing up photos on your phone | you don't need to open it. Missing a door means losing a bit of care. If you want to connect directly from the office to your home | |
| open, you can do it, but if you use a VPN, Do not forward ports |
finish with a clear order: first, turn on the SSH switch in system settings, connect with a local network computer to confirm Nendeng, use passwordless to run scripts, and turn on automatic locking. Then remember the bottom line—don't forward ports, use VPN remotely. The switch itself isn't dangerous; the real danger is that you think turning it on and it's done, so you just post it directly on the public internet.
