NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

masquerade's avatar
masquerade
Aspirant
Apr 12, 2022

Blocking inbound traffic to Port Forwarded Service

Orbi Pro SRR60 (for some reason I can add that in as the model in the discussion)

 

So I'm running a service on a VM and I have a Port Forwarding rule setup to direct inbound traffic to that service. And every so often some people can no longer connect to it while others can. There seems to be nothing that I can see in the 'logs' that indicate the issue or even that some traffic is being blocked or dropped. The only way to fix it seem to be to reboot the router.

Has anyone else seen this? What could be the cause?

5 Replies

  • CrimpOn's avatar
    CrimpOn
    Guru - Experienced User

    On the original Orbi (not any of the 'Pro' devices), the Orbi log has an option to log every instance of port forwarding/port triggering.

     

    Once a port is forwarded to a device on the LAN, that device is what accepts or denies connections. There could be a restriction in the firewall rules which blocks some IPs and accepts others?

     

    Are these failures intermittent?  i.e. the same remote user gets access some times, but does not get access other times?  If a remote user fails to get access every time, there could be an issue with the firewall rules on their end.

    • masquerade's avatar
      masquerade
      Aspirant

      Yes, the issues are intermittent, but once it occurs then it doesn't seem to fix itself. It needs me to reboot the router.

       

      Yes, it seems to always be the same remote user that gets the problem. And we have tired from multiple devices at the location and all lose access. We've tried them rebooting everything, including their internet router, but nothing fixes it. I've tried rebooting everything on my end (VM host, VM, cable modem) but none of that helps and then as soon as I reboot the Orbi, bam it works again.... for a few weeks. Then the issue seems to pop up again.

       

       

       

       

      • CrimpOn's avatar
        CrimpOn
        Guru - Experienced User

        This is really a stretch......

         

        On my old (original) Orbi, there is a choice to Disable Port Scan and DoS Protection.  (Sort of backward.  Should check something to turn it on rather than check a box to turn it off....oh, well.)  Does your Orbi Pro have a similar feature?

         

        Since I have no idea what the heck this 'feature' does (or doesn't do), I am wondering if somehow your Orbi has detected too many connection attempts from that remote IP address (which uses Network Address Translation - NAT) to represent the IPs of every computer at the remote location.  ..... and then the Orbi blocks that remote IP.

         

        I have Orbi logs emailed to me every time they fill up and keep them. It might be useful to scan a log file and see if that remote IP address appears in the Orbi logs as some sort of Denial of Service attack.

         

         

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More