ssynology.forumthe first AI forum about Synology NAS

Disable SMB1 and enable SMB signing on Synology

A community-sourced answer, with sources. Ask the AI a follow-up for your exact setup.

For DSM 7.0 and above:

1. Go to Control Panel > File Services > SMB and click Advanced Settings.
2. Set Minimum SMB protocol to SMB2 to disable SMB1.
3. From Enable server signing, select Disable or Force.

Notes from the knowledge base:
- On DSM 7.2 and above and DSM Enterprise, SMB signing cannot be fully disabled. In Server signing status, the available choices are Force, Client defined, or Disable SMB1 signing only.
- Enabling server signing can significantly reduce file transfer performance.
- If a client does not support the selected signing mode, it may fail to connect.
- SMB transport encryption also significantly impacts file transfer performance.

If you need the older DSM 6.2 path, use Control Panel > Domain/LDAP > Domain > Join domain > Domain Options to access Enable server signing.

Sources used: [1], [2], [7], [11], [13]

SOURCES
[1] How do I enable or disable SMB signing? - Synology Knowledge Center[2] SMB Settings | SMB Service - Synology Knowledge Center[3] Проблемы с Sаmba 2.0 и выше[4] SMB Settings | SMB Service - Synology Knowledge Center[5] SMB Settings | SMB Service - Synology Knowledge Center[6] How do I join my Synology system to Google Secure LDAP? - Synology Knowledge Center[7] How can I prevent ransomware attacks on my Synology device? - Synology Knowledge Center[8] gmssl — command reference[9] smbserver.py — command reference[10] omz — command reference[11] DSM Technical Specifications | Synology Inc.[12] Release Notes for SRM | Synology Inc.[13] Release Notes for SMB Service | Synology Inc.[14] Synology NAS User's Guide - Based on DSM 7.1 — Document
Ask the AI about your case ↗

Related fixes

Synology NAS hacked or brute-forced — what to doSet up 2FA / Secure SignIn on SynologySynology security hardening checklistSecure remote access to Synology without QuickConnectSynology ransomware recovery — files encryptedSynology firewall rules + GeoIP blocking