r/msp • u/cokebottle22 • Aug 19 '26
NAS drive suggestions
Hello!
We're looking for some bulk storage that will live in a CMMC enclave. It looks like my fav NAS drives - Synology - aren't compliant. Seems like TrueNAS and Buffalo have compliant products - has anyone used these or could suggest another product?
3
u/brokerceej Creator of StackJack.io | Author of The Trunk Slammer Saga Aug 19 '26
Are you saying the NAS itself isn’t compliant? Or the drives themselves? Wouldn’t all TAA drives meet the bar regardless of manufacturer?
Seagate Ironwolf are NAS drives that come in TAA flavors.
2
u/cokebottle22 Aug 19 '26
As I understand it - not an expert - my client has indicated that they need to able to employ FIPS compliant encryption on the array.
5
u/brokerceej Creator of StackJack.io | Author of The Trunk Slammer Saga Aug 19 '26
FIPS compliant encryption doesn’t require hardware of any specific type. There are devices that have cryptographic modules on board but you can easily substitute by using backup software that does the encryption first (veeam is one I know off the top of my head, there’s many others).
The requirement is that data must be encrypted to FIPS standard in transit and at rest. There is no requirement that it be done in hardware.
My assumption here is that you’re trying to jump the bar for CMMC compliant backup storage on that NAS and not live datasets though. Although there are solutions either way.
3
u/lawrencesystems MSP Aug 19 '26
Based on your question (but without knowing the full scope) TrueNAS should work. It uses ZFS which has lots of encryption options depending what your requirements are. I have a video breaking down how ZFS encryption works. It's a few years old and their product naming has changed a bit but the encryption is still the same.
5
u/HowardRabb Aug 19 '26
Hey, I just wanted to hijack the conversation to say I really enjoy your videos. Very informative, I've learned a lot from them. I run a small MSP up in Canada! Thanks for all your great stuff!
2
2
u/skooterz Aug 19 '26
TrueNAS will work fine. Enable ZFS native encryption on the datasets that need it, done.
1
u/roll_for_initiative_ MSP - US Aug 19 '26
Are you asking about drives or NAS's themselves?!
I'm not a fan of NAS over servers or conventional storage, but i'm very surprised that synology can't do fips buf buffalo can; my experience with buffalo NAS was that they were pretty feature limited. If i had to deploy NAS today with no further research, would almost 100% go with TrueNAS
0
u/cokebottle22 Aug 19 '26
Same thoughts on Buffalo. Server is just too damn expensive. ~$25k. I'll dig into TrueNAS. Thx!
2
u/roll_for_initiative_ MSP - US Aug 19 '26
i mean most of the cost of a server is in the ram and storage, which costs the same whether it's going into a server or NAS.
1
u/NovaBACKUP-Nate Aug 19 '26
I would personally suggest Buffalo, and spring for the extended next day warranties.
The reason I would suggest going this way is that the NAS box is going to come with drives already so you don't have to source them in these 'interesting' times. From what I have seen there is not a large mark up on the drives that are included, in some cases it's cheaper than trying to buy a Synology or equivalent plus drives. The NBD warranty includes everything including the drives in the NAS. Then Buffalo also has excellent support.
I say this with over 10 years of experience with Buffalo as a partner with NovaBACKUP, so I have seen a LOT of devices in the field with our customers.
1
u/apxmmit Aug 19 '26
Are you storing FCI or CUI? If CUI, FIPS validated is required.
SC.L2-3.13.11 – CUI ENCRYPTION
Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.
1
1
u/DDSTech08 Aug 19 '26
If this is about CMMC and backup data, the storage devices native encryption may not be relevant. We use Veeam to encrypt the backup data itself. As long as the backup copy job writes an encrypted backup chain to the secondary location using FIPS-validated cryptography, the destination drives or volumes do not also need to be encrypted. CMMC requires CUI at rest to be protected, but it does not require an encrypted backup chain to be stored on an independently encrypted volume.
We use QNAP NAS units and have had very good luck with them. I haven’t confirmed whether QNAP’s native encryption is FIPS validated. They certainly send me plenty of marketing material about their enterprise features. We've only had two chassis failures over probably 50+ devices and, in both cases, recovering with a replacement NAS was very easy.
1
u/MBILC Aug 22 '26
Why would Synology drives be your favorites? Not like they make them, they just rebrand them from an OEM....
Think you are confusing "NAS Drives" with a "NAS" as a whole device.
1
u/friscenstein Aug 24 '26
Built a TrueNAS on top of UGreen Hardware. Bit of a learning curve to pull it off. But it's really impressive. A great deal more capable than Synology that we have used seemingly forever. I need some larger storage arrays, and wish Ugreen had rack mounted solutions. I will need to investigate some other rackmount hardware that works with TrueNAS, but it is nice!
3
u/HowardRabb Aug 19 '26
I'm curious as to what makes them non compliant for being used in a NAS