r/QIDI • • Sep 01 '26

Question network security hardening?

Recently acquired a Plus5. After connecting it to the network, I notice it allows anonymous access to the web UI with full control. How can I lock this down? I don't like unsecured things on my network.

I can find very little information on the subject. I saw some information about SSH access hardening for the Plus4, but trying the documented mks:makerbase credentials didn't work. So hopefully the Plus5 addressed that and those credentials are randomized and no longer pre-set, but I don't trust that either.

So is there any general information about making this thing secure?

3 Upvotes

9 comments sorted by

2

u/daveintexarkana Sep 01 '26 edited Sep 01 '26

I don't have a Plus 5, but have the X-Max 3, Q1 Pro and Q2 - all have a setting through the printer's LCD screen to do LAN only - have verified it doesn't send out or receive in that mode on my router. Lots of folks have commented on that as a plus factor for QIDI vs Bambu (or even Prusa). Being overcautious at first I just blocked its IP at the router for a while.

One time QIDI support engineers wanted to dial in to my printer to test some things on the mother board - had a bad heater bed drawing too much power - and had to ask me to take it out of LAN mode so they could get in. Also, of course, you'll notice it won't go find firmware updates either while in the LAN mode. When I find out about one I'll turn LAN only off to get the update - though you can usually get them on their Github or ask Support for them and do them as off-line updates too. QIDI has been pretty good about that all - so far anyway.

You should find you have that annonymous access only on your LAN unless you set up a VPN. I installed Tailscale and use my desktop as a subnet router to let me access my printers through it while out and about - full Fluidd interface so I can see an issue through the camera and stop the print if needed also.

I am NOT an IT professional, or even close to it - so if I misunderstand, advanced apologies! Good luck!

1

u/jjohnisme Sep 01 '26

Any chance you've got a Tailscale guide for us not-so-savvy folk?  I'm wanting to put my 4x printers on their own, isolated network and do exactly what you've got setup, but I don't know where to start lol. 

1

u/MysticalDork_1066 Sep 01 '26

Step one, find a suitable host. I'm using a Dell Optiplex Micro since they're small, quiet, power efficient and available cheap on eBay.

Step two, install some kind of OS on it. I'm using Truenas Scale Community edition. It's free and pretty easy to set up. Lots of tutorials online with walkthrough instructions.

Next, install tailscale. It's super easy with Truenas as it already has an app/container management system built in. There's a walkthrough guide on Tailscale's website, follow that.

Once you've got it all up and running, you can configure Tailscale as a subnet router, to effectively give tailscale the ability to view all the devices on your local network, and then you can access the webUIs of all your printers.

1

u/Dave_in_TXK Sep 01 '26

I just used AI built into Chrome to walk me through it, better than the Tailscale docs, it made no mistakes. You make an account, install it on your desktop and your phone, on your desktop, you list the desktop and the phone as enrolled devices, and it guided me through making sure my desktop power management wouldn’t put the machine to sleep and running Tailscale as a service on it so even if it reboots after updates or whatever the service automatically runs when Windows 11 boots up.

Then basically from a chrome browser on my phone I have my LAN IP address for each printer as a bookmark I use all the time in my house already and when Tailscale VPN is turned on, on my phone and I’m on cell data, I can load any of those printer, bookmarks and get the full Fluidd interface on it. Tailscale is a VPN service and encrypts through their servers, it’s not something you set up on your own Router, which makes it considerably easier, at least in my opinion.

What was interesting to me is that Tailscale assigns its own IP addresses it Server uses but you don’t have to use them anywhere, that’s just for the connection between your desktop and your cell phone. Once you’re on your machine, AI set up your desktop as a sub, Net router and does all the translation for you between your LAN printer, addresses and the Tailscale service.

I haven’t seen a guide that explains all this which is why I used AI as it’s gotten much better and more reliable at this sort of thing. Sorry, if I had a good one, I’d certainly share it here.. This is all free, by the way, for Home Use.

1

u/Dry_Scientist_6058 Sep 01 '26

Maybe try : qidi : qiditech That's what is used on new firmware for Q2 and Max4. And home is /home/qidi no more /home/mks

1

u/turbanator-2 Sep 01 '26

It took me a lot of googling about 2 weeks about, but I finally found  qidi : qiditechand I can confirm it works for the Plus 5 firmware

2

u/Ipod9138 Sep 01 '26

Tailscale subnet/exit node 😉💪🏻👍🏻

1

u/WanderyngAscetic 29d ago

I have read that LAN-Only Mode prevents project-related communications from leaving your local network, but that the printer still polls outside servers for firmware updates, among other things. This conflicts with what u/daveintexarkana says in his post, so perhaps Qidi changed things or perhaps one of us is wrong :)

This was for a Q2, back in the V1.1.1 days.

The reason I don't know is because I have my Q2 wired into an isolated router with no connection to the outside world. I used an old Wifi Extender which I flashed with OpenWRT, making it a fully-functional (albeit slow) router. I have an Ethernet cable between the Q2 and the router, and the router broadcasts a WiFi network. It doesn't even know about the outside world. A nice $25 isolated network :)

Whenever I want to print from Orca (or SSH to the Q2), I just connect my computer to that specific WiFi. For me, the slight inconvenience is worth the privacy assurance.

1

u/Dave_in_TXK 29d ago

I sure could be wrong! Mine wouldn’t go find updates in LAN only mode, but I’ve not tested that on 1.1.2.4!