Lisar Open panel
Network storage devices

Set up Lisar on a NAS

Use the NAS client to connect to Lisar through compatible L2TP/IPsec settings or an OpenVPN profile. Keep the outbound client and remote-access server roles clear.

Connect the NAS itself to Lisar

A NAS VPN client sends traffic from the NAS through an outbound VPN connection. A VPN Server package instead accepts incoming connections to your network. Choose the client function when connecting to Lisar; installing a server or forwarding an inbound VPN port is not part of this setup.

Before you start

Open your active profile in the Lisar panel. Use its server, VPN account and IPsec values for L2TP/IPsec, or its downloaded .ovpn file for OpenVPN. Your website sign-in password is not automatically your VPN password.

Start with L2TP/IPsec where the device, firmware and network support a suitable connection. OpenVPN is the alternative where they do not. Only those two protocols are covered here; other options offered by a device are not Lisar connection methods.

Confirm your NAS model, operating-system release and VPN client options. Save its current network configuration and retain a local management path before changing default routes. If the NAS already runs backups, remote access or virtual machines, plan a small connection test before routing those workloads.

Use the values supplied with your profile, including certificate material when required. Do not replace a missing field with an example from a different provider or disable certificate validation to force a connection.

Synology DSM

In Control Panel → Network → Network Interface, choose Create → Create VPN profile. DSM documents L2TP/IPsec and OpenVPN client profiles. Start with compatible L2TP/IPsec using your server, VPN account, password and pre-shared key.

For OpenVPN, choose the .ovpn import method and load the file and any additional certificate or authentication values required by the profile. Synology documents layer-3 TUN support; do not assume a TAP profile is compatible.

Save the profile, select it and connect. Use default gateway on remote network changes the NAS's route. The option to let other devices use the NAS connection is separate; leave it unchanged unless you are intentionally designing that shared gateway. DSM documents one active VPN profile at a time.

Synology: DSM VPN client profiles, routing options and limitations

QNAP with QVPN Service

Open QVPN Service on a supported QNAP NAS, then VPN Client → VPN Connection Profiles → Add. Select a compatible L2TP/IPsec connection or the OpenVPN alternative and complete its profile-specific settings. For OpenVPN, import the supplied file and any required VPN authentication details.

Create the profile, connect it and check its status and connection log. Use VPN as NAS Default Gateway is a separate routing choice. Review it before enabling it, especially if management or backup services currently depend on another route.

These instructions use the NAS application QVPN Service. QVPN Client for desktop or mobile is a separate application; follow its own client documentation if you use it on another device. QNAP's QBelt protocol is not a Lisar connection method.

QNAP: QVPN Service client profiles and NAS default gateway

ASUSTOR ADM

ASUSTOR documents an OpenVPN client in its Network/VPN settings. Open the VPN client settings in your ADM release, add an OpenVPN connection and use the Lisar configuration file and authentication details required by the profile.

Use the client function, then connect and check the connection state. The current client documentation supports the OpenVPN path here; a separate VPN Server feature advertising L2TP/IPsec does not prove that the NAS has the corresponding outbound client.

Menus and accepted configuration options depend on the ADM release. If you cannot map a field to the supplied profile, record its name and ask for help before changing the profile or running an unofficial startup script.

ASUSTOR: Network settings and VPN client protocols

Check NAS routing, applications and containers

  1. Confirm an established VPN connection in the NAS interface and that the intended workload can reach its destination.
  2. Check routing and DNS from the NAS or the relevant application. A browser on your laptop tests the laptop's route, not the NAS route.
  3. Test local management and file access from your LAN after any default-gateway change.
  4. For containers and virtual machines, inspect their network mode and routes separately. A host VPN connection is not proof that every isolated workload uses it.
  5. Reconnect once during the planned test and verify how affected tasks recover. Restore the previous route if essential management or backup access is lost.

If you want the whole network to use Lisar, the router guide is the appropriate starting point. A NAS client does not automatically route every other device on the LAN.

An outbound Lisar connection does not automatically expose NAS files to remote users, replace a backup plan or set up a private company network. Use the NAS manufacturer's separate remote-access guidance for that goal. For help with this connection, provide your NAS model, OS/client version, protocol and a redacted error through Contact Lisar.

More setup help

Contact Lisar

Get help with a profile or a device-specific setup problem.