NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

gabegarcia's avatar
gabegarcia
Aspirant
Mar 28, 2021
Solved

Orbi CBR40 Getting DoS attack: snmpQueryDrop

Hello,   Is Obri blocking these DDoS attacks?   I'm seeing about 10 attacks per day in the logs. I've checked their IP's and they are not the false positive scenarios like Facebook, Amazon, or Dr...
  • CrimpOn's avatar
    Mar 29, 2021

    gabegarcia wrote:

    Is Obri blocking these DDoS attacks?

    I'm seeing about 10 attacks per day in the logs. I've checked their IP's and they are not the false positive scenarios like Facebook, Amazon, or Dropbox. 

    Should I be concerned?


    Yes, Orbi's firewall does not accept connection attempts from the internet until the user deliberately sets up either port forwarding, Remote Administration, or OpenVPN.  These log entries are the result of firewall logic which collects connection requests and attempts to assign them to categories.  I monitor two Orbi systems and they both regularly log about 30 of these "attacks" every day. (Yes, every day.)  I have seen comments that Netgear's logic is flowed and logs things as "attacks" that are not.

     

    I do not recall seeing any "snmp" events in my log files.

     

    Be Concerned?  I think not.  If you would rather not see the entries in the log file, there is an option to stop logging them.