diff --git a/docs/deployment/synology-rt2600ac-checklist.md b/docs/deployment/synology-rt2600ac-checklist.md index 17291b7..e3cfb3b 100644 --- a/docs/deployment/synology-rt2600ac-checklist.md +++ b/docs/deployment/synology-rt2600ac-checklist.md @@ -1,6 +1,6 @@ # Synology RT2600ac — Fleet Deployment Checklist -**Version:** 1.1 · **Last updated:** 2026-07-21 · **Audited against:** x4078 DSS config backup +**Version:** 1.2 · **Last updated:** 2026-07-22 · **Audited against:** x4078 DSS config backup Every Synology RT2600ac bus router MUST pass ALL sections before departing the yard. Items flagged 🔴 were missed on x4078 and caused remote-access emergencies. @@ -50,6 +50,45 @@ Every Synology RT2600ac bus router MUST pass ALL sections before departing the y - Email: configure SMTP or use SRM notification relay - [ ] **2.5** **SSH:** Control Panel → Terminal & SNMP → Enable SSH on port 2223 - [ ] **2.6** **Regional Options:** Verify language, time format, and date format +- [ ] **2.7** 🔴 **Disable WPS:** Wi-Fi Connect → WPS → **Disabled** on both bands +- [ ] **2.8** 🔴 **Login page title:** Control Panel → System → Login Portal → Title = `` (e.g. `x5925`) +- [ ] **2.9** 🔴 **Sign in to Synology Account:** Control Panel → QuickConnect → Sign in with Synology Account + - Required for QuickConnect relay to work. Use `pioneercoach@keylinkit.net` or create if needed. +- [ ] **2.10** 🔴 **Do NOT use DoH:** Network Center → Internet → DNS → Do NOT use DNS over HTTPS + - Standard DNS only: `1.1.1.2`, `9.9.9.9`, `8.8.8.8` + +--- + +## 2b. Security — Safe Access + +- [ ] **2b.1** 🔴 **Install Safe Access:** Package Center → Install "Safe Access" (Synology SRM package) +- [ ] **2b.2** 🔴 **Enable malware blocking on Primary network:** + - Safe Access → Primary Network → Web Filter → Block malicious websites + - Enable **Google Safe Browsing** +- [ ] **2b.3** 🔴 **Enable malware blocking on Guest network:** + - Safe Access → Guest Network → Web Filter → Block malicious websites + - Enable Google Safe Browsing +- [ ] **2b.4** 🔴 **Google Safe Browsing API key:** Use `AIzaSyBqjLxf1BpD-gPgMqOV1whr6KtomP_D3MM` +- [ ] **2b.5** 🔴 **Enable Threat Intelligence database:** Safe Access → Settings → Threat Intelligence → ON + - Auto-update definitions +- [ ] **2b.6** 🔴 **DoS Protection:** Network Center → Security → DoS Protection → **Enabled** +- [ ] **2b.7** **Safe Access profiles:** Create a profile for fleet devices with appropriate filtering + +--- + +## 2c. Traffic Control — Bandwidth Management + +- [ ] **2c.1** 🔴 **Enable Traffic Control:** Network Center → Traffic Control → Enable +- [ ] **2c.2** 🔴 **Per-device throttle:** Set maximum bandwidth per client to **80% of total WAN capacity** + - Dynamic: adjust based on measured WAN speed + - Guest network: stricter cap (50% of total) +- [ ] **2c.3** 🔴 **Run speed test on new WAN detection:** + - When a WAN interface comes up for the first time, run a speed test to measure capacity + - Set traffic control caps based on measured throughput + - Re-test if WAN IP changes (new ISP/tower) +- [ ] **2c.4** **QoS priority:** Primary network gets higher priority than Guest + - Primary: 70% guaranteed minimum + - Guest: 30% maximum (burst to 50% when idle) --- @@ -212,6 +251,11 @@ Every Synology RT2600ac bus router MUST pass ALL sections before departing the y | Backup cron | `grep backup /etc/crontab` | present | | Auto-update | SRM UI → Update & Restore | Auto-check ON | | Notifications | SRM UI → Notification | Enabled | +| WPS | Wi-Fi Connect → WPS | Disabled both bands | +| Safe Access | Package Center → Safe Access | Installed, malware ON | +| DoS Protection | Network Center → Security | Enabled | +| Traffic Control | Network Center → Traffic Control | Enabled, 80% cap | +| DoH | Network Center → Internet → DNS | OFF | - [ ] **10.3** 🔴 **Run the reboot test before the bus leaves the yard.** There is no second chance. - [ ] **10.4** Store credentials in vault under `busrouter/`