The NAS is not in the DMZ, but 22 forwarded. I could change the incoming port to something different to prevent that I guess. As long as I know the port it is all that matters Only my SIP router is in the DMZ (the VoIP folks can get at it easily and QoS is not an issue). That is not absolutely neccesary and I might go back to forwarding the right ports and putting it on the GS116E switch with 802.1P to manage it.
I have ssh open on the NAS and just recovered from a bricked GUI by doing a firmware update. You were a principle in that thread (...Cannot access the dashboard...)