NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
GCCJay
Dec 20, 2021Aspirant
Nessus Professional Vulnerability scan kills internet connectivity through SXR80
Our setup:
We have two completely separate, physically isolated networks. One is our corporate network with no wi-fi, and the second is a simple business grade cable-internet that we use solely to provide our customers free public wi-fi using a fairly new Netgear Orbi Pro WiFi 6 SXK80 kit with a router and 2 satellites. The Orbi system replaced a Netgear R6300v2 wi-fi router earlier this year.
The issue:
For at least the last 4 years, we have utilized Tenable Nessus Professional for quarterly external vulnerability scans of our corporate network's public IP space. To do this, we connect our Nessus scanning laptop to the cable internet connection that we use for public wi-fi access. Through previous Netgear routers this has never been an issue, and the scans have always completed just fine. However once we replaced the R6300v2 router with the Orbi system, running the Nessus scan through this device completely hoses up the internet connection through the SXR80 (meaning internet access just stops, with all devices reporting no internet access even though they are still connected to the wi-fi network), with the only resolution being to power cycle the SXR80. The cable modem and ISP is apparently not the issue, because the only thing that changed was moving from a R6300v2 to the Orbi Pro router. I could potentially see if the Netgear Orbi was the target of the scan, but this is not the case. The scan is originating from the Orbi, and the scan targets are our corporate nework's public IP addresses (less than 2 dozen IPs). I opened a ticket with Tenable support, and they recommended slowing the scans down and trying again, to no avail. They then stated we would need to open a support request through the device manufacturer to investigate, but of course Netgear's included support is amazingly only for 3 months, which in itself is sad for such an expensive business-focused product (it's not like this thing was cheap).
I have played around with every possible setting in the router that I could think of that may be causing it to get hosed up by the scan, but nothing has made any difference. Anyone have any ideas? Thanks in advance.
5 Replies
- GCCJayAspirant
Hi Raghu,
The debug page won't allow me to save debug logs without first initiating a capture. Do I need to run the Nessus scan again and reproduce the issue while the router is capturing the debug logs?
- RaghuHRNETGEAR Expert
Yes start capture, recreate the issue and then save the debug logs.
Thanks,
Raghu
Related Content
NETGEAR Academy
Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!