NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
dwax
Jul 15, 2021Guide
Orbi RBR850 crashes with large downloads
My kids and thier gaming require large downloads from battle.net and Epic games. These downloads are often greater than 100GB. When they start to download the router RBR850 loses its connection t...
- Aug 29, 2022
My Orbi 750 is running Firmware Version V4.6.8.2_2.1.9. Support suggested turning off Armor and that stopped the crashing. Awaiting a real resolution since paying for Armor but having to have it disabled for a game to download from Steam shouldn't be the solution.
LokiThorne
Jan 20, 2022Aspirant
I just got a new PC running Win11. For the first time, I'm using Ethernet and I'm getting this issue when trying to DL games from Battle.net. I did NOT exhibit this problem when getting games from Steam. I'll run a test on the Xbox app later today. What I did find out was pulling the Ethernet plug and turning on WiFi seems to have stopped this issue.
My system has an Asus Z690-P MB with:
WiFi: Intel AX201
Ethernet: Realtek Gaming 2.5G
My ethernet connection is going through a Netgear GS305 switch. I don't think it's gonna be an ethernet protocol issue with the computer since the switch would be rebuilding the packet (replacing MAC address, etc) so it should be catching protocol issues. If I had to guess, we really are seeing a DoS attack on the switch itself. Seems like when it gets a connection that ramps up too fast, it kills the router. My link speed on WiFi is 576/649 Mbps, so that probably isn't triggering the attack. If I have time this weekend, I'll play around and see what the magic DL speed is that triggers this bug. I think it should probably get sent up as a security issue since we are seeing a DoS getting triggered.
FURRYe38
Jan 20, 2022Guru - Experienced User
What Firmware version is currently loaded?
What is the Mfr and model# of the Internet Service Providers modem/ONT the NG router is connected too?
LokiThorne wrote:
I just got a new PC running Win11. For the first time, I'm using Ethernet and I'm getting this issue when trying to DL games from Battle.net. I did NOT exhibit this problem when getting games from Steam. I'll run a test on the Xbox app later today. What I did find out was pulling the Ethernet plug and turning on WiFi seems to have stopped this issue.
My system has an Asus Z690-P MB with:
WiFi: Intel AX201
Ethernet: Realtek Gaming 2.5G
My ethernet connection is going through a Netgear GS305 switch. I don't think it's gonna be an ethernet protocol issue with the computer since the switch would be rebuilding the packet (replacing MAC address, etc) so it should be catching protocol issues. If I had to guess, we really are seeing a DoS attack on the switch itself. Seems like when it gets a connection that ramps up too fast, it kills the router. My link speed on WiFi is 576/649 Mbps, so that probably isn't triggering the attack. If I have time this weekend, I'll play around and see what the magic DL speed is that triggers this bug. I think it should probably get sent up as a security issue since we are seeing a DoS getting triggered.
- LokiThorneJan 21, 2022Aspirant
Orbi Firmware: V4.6.3.16_2.0.51
Cable Modem
Model:CGM4331COMVendor:TechnicolorJust a few thoughts:
I'm not sure the upstream device has much to do with this, as Orbi goes completely offline. The internal side drops, and you are unable to access the web UI when the DoS happens. Based on the testing I've performed, the high rate transfers that I get off the Blizzard app when connected to Ethernet seems to cause an almost immediate DoS. I do wonder about the Blizzard app, though. That seems to be an odd common thread. I wonder if it doing some kind of multi-point connection that is killing the router network stack?
- SQUIDWARD360Jan 21, 2022GuideTry the Epic Games app also. Same issue. Moving it to WiFi did fix the issue. But that wasn't a suitable workaround for me and I ditched the Orbi.
- jimhayesJan 21, 2022Aspirant
I ditched the Orbi as well - back to Erro
- FURRYe38Jan 21, 2022Guru - Experienced User
Your ISP Modem already has a built in router and wifi. This would be a double NAT (two router) condition which isn't recommended. https://kb.netgear.com/30186/What-is-Double-NAT
https://kb.netgear.com/30187/How-to-fix-issues-with-Double-NAT
Couple of options,
1. Configure the modem for transparent bridge or modem only mode. Then use the Orbi router in router mode. You'll need to contact the ISP for help and information in regards to the modem being bridged correctly.
2. If you can't bridge the modem, disable ALL wifi radios on the modem, configure the modems DMZ/ExposedHost or IP Pass-Through for the IP address the Orbi router gets from the modem. Then you can use the Orbi router in Router mode.
3. Or disable all wifi radios on the modem and connect the Orbi router to the modem, configure AP mode on the Orbi router. https://kb.netgear.com/31218/How-do-I-configure-my-Orbi-router-to-act-as-an-access-point and https://www.youtube.com/watch?v=H7LOcJ8GdDo&app=desktopTry Option #2 first. if not, try option #3.
Also review this:
v16 FW has been problmatic for lots of users.
I have not seen any game download issues to date on my 8 series Orbi. However I don't have same modem.
LokiThorne wrote:
Orbi Firmware: V4.6.3.16_2.0.51
Cable Modem
Model:CGM4331COMVendor:TechnicolorJust a few thoughts:
I'm not sure the upstream device has much to do with this, as Orbi goes completely offline. The internal side drops, and you are unable to access the web UI when the DoS happens. Based on the testing I've performed, the high rate transfers that I get off the Blizzard app when connected to Ethernet seems to cause an almost immediate DoS. I do wonder about the Blizzard app, though. That seems to be an odd common thread. I wonder if it doing some kind of multi-point connection that is killing the router network stack?
- LokiThorneJan 21, 2022Aspirant
I apologize for not explaining better. I'm a Cybersecurity Engineer by trade, and I've already got the network topology configured per your recommendations. The ISP modem is in bridge mode with the radio turned off, with an internal 192.168.1.x net behind it. The Orbi is connected directly to it and located in the same cabinet (house is pre-wired for networking). The WAN side of the Orbi is getting a 192.168.1.x address from the modem, and has an interior network of 192.168.0.x with a mix of ethernet and WiFi hosts connecting to it and it's single satellite. Given that the Orbi is dropping it's internal network interface, it would be difficult to imagine a scenario where the ISP router could cause the Orbi to drop under any normal circumstances . Hence, this is likely more related to a firmware bug in the Orbi itself.
The interesting thing is that my Orbi claims to be at the most current firmware release so I'm guessing that this firmware update is still in testing. I need my network stable for work (both my wife and I work remote), so I'm not too interested in updating until it's in full release.
For Netgear:
I do believe that this vuln should be reported to NVD though as it has to potential to take down the router and seems to require a cold boot to fix. I'd ask that a representative from Netgear report this appropriately and document any workarounds/fix. I'm a firm believer that companies need to self report, but if that's not their business process then I'll be happy to collect the packet traces and report to NVD myself, but coordination with the security community would be a much better approach as a company.