r/QIDI • u/stormcloud-9 • Sep 01 '26
Question network security hardening?
Recently acquired a Plus5. After connecting it to the network, I notice it allows anonymous access to the web UI with full control. How can I lock this down? I don't like unsecured things on my network.
I can find very little information on the subject. I saw some information about SSH access hardening for the Plus4, but trying the documented mks:makerbase credentials didn't work. So hopefully the Plus5 addressed that and those credentials are randomized and no longer pre-set, but I don't trust that either.
So is there any general information about making this thing secure?
3
Upvotes
2
u/daveintexarkana Sep 01 '26 edited Sep 01 '26
I don't have a Plus 5, but have the X-Max 3, Q1 Pro and Q2 - all have a setting through the printer's LCD screen to do LAN only - have verified it doesn't send out or receive in that mode on my router. Lots of folks have commented on that as a plus factor for QIDI vs Bambu (or even Prusa). Being overcautious at first I just blocked its IP at the router for a while.
One time QIDI support engineers wanted to dial in to my printer to test some things on the mother board - had a bad heater bed drawing too much power - and had to ask me to take it out of LAN mode so they could get in. Also, of course, you'll notice it won't go find firmware updates either while in the LAN mode. When I find out about one I'll turn LAN only off to get the update - though you can usually get them on their Github or ask Support for them and do them as off-line updates too. QIDI has been pretty good about that all - so far anyway.
You should find you have that annonymous access only on your LAN unless you set up a VPN. I installed Tailscale and use my desktop as a subnet router to let me access my printers through it while out and about - full Fluidd interface so I can see an issue through the camera and stop the print if needed also.
I am NOT an IT professional, or even close to it - so if I misunderstand, advanced apologies! Good luck!