File Services & Protocols
DSM Version
7.4 7.3 7.2

File Services & Protocols

SMB Protocol

Connectivity & Protocol Versions

  • Up to 10,000 concurrent SMB connections (capacity varies depending on product model)
  • Supports end-to-end SMB1, SMB2, SMB3 encryption and Large MTU
  • Limitations
    • The minimum SMB protocol cannot be set to SMB3. As SMB3 on DSM refers to SMB3.1.1, setting SMB3 as the minimum SMB protocol will prevent client devices supporting earlier SMB3 versions from accessing Synology NAS via the SMB protocol
    • Concurrent connections (up to 10,000) are shared between SMB, AFP, and FTP protocols
    • Workgroup name can contain up to 15 characters but cannot include the following characters: [ ] ; : " < > * + = \ / | ? ,

File & Folder Management

  • Flexible option to restore Previous Versions of files and folders on Windows
  • Supports full Windows ACL with up to 200 explicit permissions
  • Supports Recycle Bin
  • Supports server-side copy on Windows
  • Supports File Fast Clone on Btrfs file system
  • Supports sparse file
  • Supports Time Machine on macOS 10.12 and later versions
  • Supports hiding shared folders from users without permission
  • Supports Aggregation Portal, using technology based on Microsoft's Distributed File System (DFS)
  • Limitation: Disallowing access to Previous Versions is only available on vDSM and product models with the following package architectures: Apollo Lake, Avoton, Braswell, Broadwell, Bromolow, Cedarview, and Grantley (see this article for information on Synology NAS system models and corresponding package architectures)

Search Integration

  • Integration with Universal Search enables quick and in-depth search of indexed documents, photos, and other contents within mounted folders on Synology NAS
  • Integrated with Synology Universal Search:
    • Finder on Mac
    • File Explorer on Windows
    • Limitation: Integration with File Explorer on Windows and Finder on Mac to search for indexed folders via the SMB protocol is not available on NVR devices

Kerberos Authentication

  • Supports Kerberos authentication, allowing domain and LDAP clients to securely access data through SMB services
  • Requires proper Kerberos configuration in supporting infrastructure, such as the Key Distribution Center (KDC) and DNS server
  • Requires a Kerberos Service Principal Name (SPN) beginning with "cifs/" configured in your Active Directory (AD) or KDC environment
  • For LDAP environments:
    • A keytab file must be imported manually
    • Only .keytab files are supported
    • The maximum keytab file size is 500 KB
    • Importing a new keytab file overwrites the existing one
  • For Active Directory (AD) environments:
    • The keytab file is imported automatically

Transfer Logging

  • Supports transfer logs to monitor and record file operations. When transfer logging is enabled:
    • Logging file deletion and renaming by default
    • Other file operations can be selected for monitoring in Log Settings
  • Limitation: The more file operation events you select in Log Settings, the more impact it will have on system performance

Advanced SMB Options

  • Advanced SMB options include
    • General
      • WINS server
      • Access settings for selected SMB versions
      • Transport encryption mode on SMB3
      • Server signing
      • Opportunistic Locking (SMB2 file leasing and SMB3 directory leasing)
      • SMB durable handles
      • Clear SMB cache
    • macOS
      • VFS module to convert Mac special characters
      • Cross-protocol locking with AFP
    • Others
      • Local Master Browser
      • DirSort VFS module
      • Veto files
      • Symbolic links
      • Disabling multiple connections from the same IP address
      • Debugging logs
      • Applying default UNIX permissions
      • Strict allocate
      • Authenticating NTLMv1
      • Asynchronous read
      • Monitoring changes on all subfolders within the directory
      • Synchronizing data to drive immediately upon SMB client request
      • Wildcard search cache
      • SMB3 Multichannel (see dedicated section below)
  • Limitations
    • Anonymous logon for the SMB protocol is not supported when transport encryption mode is enabled
    • Opportunistic Locking should be disabled to avoid application timeouts when transport encryption mode is enabled
    • Opportunistic Locking currently detects only metadata and access changes made through SMB
    • Enabling Local Master Browser will disable HDD hibernation and activate the guest account without a password
    • Enabling transport encryption mode or server signing may reduce read/write performance during SMB file transfer

SMB3 Multichannel

  • Available only on Synology NAS models running DSM 7.1.1 or above and using SMB Service 4.15
  • Only supports models using x86 platforms, which are as listed in Applied Models of this article
  • Supports the following client operating systems:
    • Windows Server 2012 and above
    • Windows 8 and above
    • macOS 11.3 and above
  • Either of the following must be installed on both server and client:
    • Multiple network adapters
    • One or more network adapters that support RSS (Receive Side Scaling)
  • Limitations:
    • Enabling SMB3 Multichannel enables asynchronous read
    • SMB3 Multichannel and Link Aggregation cannot be enabled concurrently
    • Does not support RDMA (Remote Direct Memory Access)

AFP Protocol

Connectivity

  • Up to 10,000 concurrent AFP connections (capacity varies depending on product model)
  • Limitation: Concurrent connections (up to 10,000) are shared between SMB, AFP, and FTP protocols

Search Integration

  • Integrates Finder on Mac with Synology Universal Search
  • Limitations
    • Integration with Finder on Mac to search for indexed folders is not available on NVR (Network Video Recorder) series
    • Integration with Finder on Mac to search mounted folders by tag name and category is only available on macOS 10.9 and later versions

macOS & File Management

  • Supports Time Machine on macOS
  • Supports Bonjour Time Machine broadcast
  • Supports File Fast Clone on Btrfs file system
  • Supports extended file attributes for color label/icon/extra information on macOS
  • Supports Recycle Bin
  • Supports transfer logs to monitor records of file manipulation
  • Advanced AFP options
    • Apply default UNIX permissions
    • Release resources immediately after disconnection

Shared Folder Limits

  • Limitation: Only a maximum of 255 shared folders can be displayed (in alphabetical order) when being accessed via the AFP protocol; however, the total number of created shared folders may exceed that number

FTP Protocol

Connectivity

  • Up to 10,000 concurrent FTP connections (capacity varies depending on product model)
  • Customized port ranges for passive FTP connections
  • Server-to-server file transfer via FXP (File eXchange Protocol)
  • Limitation: Server cannot be accessed via the FTP protocol by the "guest" account

Protocol & Security

  • Supports FTP, FTP over SSL/TLS (explicit mode), and SFTP protocols
  • Supports connection restriction settings for IP addresses
  • Supports timeout settings to disconnect idle users

Transfer Settings

  • Speed limit settings for specific users or groups
  • Supports ASCII transfer mode
  • Supports UTF-8 encoding for files with multilingual filenames
  • Supports Recycle Bin
  • Advanced FTP options
    • Root directory for each user
    • Anonymous FTP
    • Transfer logs
    • Apply default UNIX permissions

NFS Protocol

Protocol Support

  • Supports NFS version 2, 3, 4, and 4.1 protocols
  • Supports NFS version 4.1 multipathing
  • Supports Kerberos authentication, allowing domain and LDAP clients to securely access data through NFS services
  • Applies default UNIX permissions
  • Supports customized service ports
  • Supports read/write UDP packet size settings
  • Provides squash options: no mapping, root-to-admin/guest mapping, and all-users-to-admin/guest mapping
  • Supports asynchronous writes for better performance
  • Allows connections from non-privileged ports (ports higher than 1024)
  • Allows access to mounted subfolders
  • Limitations
    • NFS version 4.1 protocol is only supported on specific product models. Learn more
    • Shared folders using HFS Plus and exFAT file systems are not accessible via NFS

Rsync

Protocol & Configuration

  • Supports rsync version 3.1.2 protocol
  • Supports customized rsync configuration to assign user privileges
  • Supports SSH encryption protocol during file transfer
  • Supports SSH port customization
  • Speed limit settings (scheduled and non-scheduled) for specific users or groups

Supported Use Cases

  • Packages and services running the rsync protocol:
    • Shared Folder Sync
    • LUN backup
    • rsync backup
  • Limitation: To perform rsync backup from a Synology NAS running a version of DSM before 3.0 or a client that is not a Synology NAS, and to retain the source data's owner and group information, you must add the rsync accounts to the administrators group, and back up data to the NetBackup shared folder in the daemon mode