Skip to content

4. Base Configuration

Perform these steps right after installation, before putting the system into production use.

4.1 First login and password

  1. Open https://<node IP or VIP>:8443/ in a browser and accept the self-signed certificate warning (expected until a real TLS certificate is uploaded).
  2. Log in with admin / nascore-admin.
  3. Go to Users and set a new password for the admin account immediately.
  4. Create any additional accounts needed (admin or read-only roles) from the same page.

4.2 Network, NTP and timezone

Configuration → Network shows the current bond0/bond1 addresses and lets you adjust DNS, NTP and timezone without re-running the installer:

  • DNS and NTP changes apply immediately (chrony restarts automatically) — no confirmation window.
  • A data-network (bond0) IP/gateway change is staged with an automatic revert if not confirmed within the timeout window, since a mistake there can cut off GUI access.
  • Timezone only affects how timestamps are displayed (GUI, SMB clients); NTP is what actually keeps the clock correct. Set the same timezone and NTP source(s) on both cluster nodes for consistent file timestamps across the shares regardless of which node is active.

4.3 Firewall

Configuration → Firewall shows the default ruleset (SSH/GUI/NFS/SMB/rsync/S3 open on the data network, everything else closed; cluster peers and the heartbeat network are always trusted). Review it and click Apply — this uses a confirm-or-auto-revert safety window, same reasoning as the network IP change above. Custom rules can be added afterward and replicate automatically to the peer node in a cluster.

4.4 Security features

Configuration → Security features turns on baseline host hardening: auditd (audit logging), fail2ban (SSH brute-force protection) and AIDE (file-integrity monitoring). Recommended to enable on any system that will hold real data.

Note

fail2ban will lock out a source IP after repeated failed SSH login attempts (default: 5 failures / 10 minutes, 10-minute ban). See Troubleshooting if you get locked out during your own testing.

4.5 Data protection

  • Data protection → Snapshots — set a local ZFS snapshot schedule per share.
  • Data protection → S3 external target — define a restic/S3 backup destination (optional; needed before shares or the config backup below can back up offsite).
  • Data protection → Config backup — the platform's own configuration (users, firewall rules, schedules, etc.) is backed up locally on a daily timer automatically; pick an S3 target here to also copy it offsite.
  • Data protection → Backup status — shows the history of every backup run, on either node.

4.6 Create the first share

  1. Storage services → Shares → Add share.
  2. Choose the protocol(s) to expose it over (NFS, SMB, rsync) and the export options.
  3. Save — the share becomes available immediately over the protocols selected.

4.7 License activation

Configuration → Product license accepts an activation token issued by NearZero. Until activated, the platform runs in a limited grace period; some features (including software updates) are gated on a valid license.

4.8 Verify cluster health (cluster role only)

From the GUI's Cluster status page, or the console, confirm the cluster is quorate and every resource is started before considering the install complete. A healthy 2-node-plus-quorum-device cluster reports 3 possible votes and quorate status.