NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

SonofSouthie's avatar
SonofSouthie
Aspirant
Jul 20, 2026
Solved

Getting Bombed With DDos Attacks

Since switching to a CAX30 from a C7000v2 a month ago, as noted in the subject headline, Norton has blocked them effectively. This one was the most recent, and the IP address is Comcast in Burlington, VT. Comcast security has been notified.

 

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 14:06:57

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 14:06:57

[DHCP IP: (192.168.1.2)] to MAC address e4:54:e8:b8:3e:4b, Jul 20 09:41:02

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 13:18:42

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 13:18:42

[DHCP IP: (192.168.1.2)] to MAC address e4:54:e8:b8:3e:4b, Jul 20 09:17:38

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 13:06:42

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 13:06:42

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 12:54:41

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 12:54:41

[DHCP IP: (192.168.1.2)] to MAC address e4:54:e8:b8:3e:4b, Jul 20 08:31:33

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 12:30:31

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 12:30:31

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 12:06:22

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 12:06:22

[DHCP IP: (192.168.1.3)] to MAC address 74:40:be:47:4f:f6, Jul 20 08:02:54

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 11:42:21

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 11:42:21

[DHCP IP: (192.168.1.2)] to MAC address e4:54:e8:b8:3e:4b, Jul 20 07:31:48

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 11:30:21

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 11:30:21

[DHCP IP: (192.168.1.5)] to MAC address e6:57:8a:e0:4d:2f, Jul 20 07:25:01

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 11:18:19

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 11:18:19

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 11:06:16

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 11:06:16

[DHCP IP: (192.168.1.2)] to MAC address e4:54:e8:b8:3e:4b, Jul 20 07:01:03

[DHCP IP: (192.168.1.2)] to MAC address e4:54:e8:b8:3e:4b, Jul 20 06:58:04

[DHCP IP: (192.168.1.2)] to MAC address e4:54:e8:b8:3e:4b, Jul 20 06:57:58

[DHCP IP: (192.168.1.2)] to MAC address e4:54:e8:b8:3e:4b, Jul 20 06:48:11

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 10:42:11

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 10:42:11

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 10:30:11

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 10:30:11

[DHCP IP: (192.168.1.3)] to MAC address 74:40:be:47:4f:f6, Jul 20 06:29:00

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 10:18:11

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 10:18:11

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 09:54:01

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 09:54:01

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 09:30:01

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 09:30:01

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 09:05:52

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 09:05:52

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 08:53:51

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 08:53:51

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 08:29:51

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 08:29:51

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 07:53:41

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 07:53:41

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 07:41:41

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 07:41:41

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 07:29:41

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 07:29:41

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 06:53:41

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 06:53:41

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 06:17:41

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 06:17:41

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 05:53:41

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 05:53:41

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 05:41:41

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 05:41:41

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 05:17:41

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 05:17:41

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 04:17:41

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 04:17:41

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 03:17:41

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 03:17:41

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 02:53:41

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 02:53:41

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 02:29:41

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 02:29:41

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 02:17:41

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 02:17:41

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 01:17:41

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 01:17:41

[DHCP IP: (192.168.1.3)] to MAC address 74:40:be:47:4f:f6, Jul 19 21:07:41

[DHCP IP: (192.168.1.2)] to MAC address e4:54:e8:b8:3e:4b, Jul 19 20:38:43

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 00:18:21

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 00:18:21

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 19 23:59:21

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 19 23:59:21

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 19 23:51:12

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 19 23:44:12

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 19 23:44:12

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 19 23:38:09

[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 19 23:38:09

[DHCP IP: (192.168.1.3)] to MAC address 74:40:be:47:4f:f6, Jul 19 19:29:11

[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 137, Jul 19 23:28:24

ioned attacks every day(I check security logs).

  • Thanks.  As FURRYe38​ pointed out, it is not Norton that is detecting these "attacks".    Netgear routers do not accept connection attempts unless the owner has specifically defined ports to "forward" to specific devices on the local network.

     

    The CAX30 has a feature that can make entries in the router log file when its software "detects" what it considers to be an "attack".  On my RBR50 there is an option:

    This option controls whether these events are recorded in the log.  (It does not affect whether the router accepts connections or not).

     

    Several users have posted recently that when they replace an older "R-series" Netgear router with a newer model, the log suddenly started filling up with these "attacks".  The simple fact is that any device connected to the internet will attract connection attempts.  They cannot be stopped.  (Just as a mailbox will receive "junk mail" and a telephone will receive marketing calls.)  The R7000 did not fill up the log file with these reports, and the CAX30 does.  Your choice is whether to look at them or not.

9 Replies

  • FURRYe38's avatar
    FURRYe38
    Guru - Experienced User

    Will need to keep in contact with the ISP for that IP address. 

    CAX30 is just reporting what's happening. Hopefully the ISP can figure it out. 

     

     

  • Thx. I keep getting some attacks from different IP addresses, check the addresses via iplocation.com, and they all belong to Digital Ocean. I contact them and get a reply, "We'll tell our customers to stop"

    • FURRYe38's avatar
      FURRYe38
      Guru - Experienced User

      Might ask the ISP to change the WAN IP address as well. 

      The firewall on the CAX is working. Just the logs are reporting what is happening is all.

       

      SonofSouthie wrote:

      Thx. I keep getting some attacks from different IP addresses, check the addresses via iplocation.com, and they all belong to Digital Ocean. I contact them and get a reply, "We'll tell our customers to stop"

       

  • Is that list of "attacks" from:

    • The CAX30 log file, or
    • From Norton on a PC?

     

  • Thanks.  As FURRYe38​ pointed out, it is not Norton that is detecting these "attacks".    Netgear routers do not accept connection attempts unless the owner has specifically defined ports to "forward" to specific devices on the local network.

     

    The CAX30 has a feature that can make entries in the router log file when its software "detects" what it considers to be an "attack".  On my RBR50 there is an option:

    This option controls whether these events are recorded in the log.  (It does not affect whether the router accepts connections or not).

     

    Several users have posted recently that when they replace an older "R-series" Netgear router with a newer model, the log suddenly started filling up with these "attacks".  The simple fact is that any device connected to the internet will attract connection attempts.  They cannot be stopped.  (Just as a mailbox will receive "junk mail" and a telephone will receive marketing calls.)  The R7000 did not fill up the log file with these reports, and the CAX30 does.  Your choice is whether to look at them or not.

  • schumaku's avatar
    schumaku
    Guru - Experienced User
    FURRYe38 wrote:

    CAX30 is just reporting what's happening.

     

    Typical false Netgear home-made positive of return traffic due to a wonky consumer router implementation.

     

    Its about retrun traffic used form your own honme network, devices, computers, ... accessing whatver cloud or Web services , hosted on Digital Ocean.

     

    Issue exists for virtually decades, the same decades old code is re-used on all router generations. Nothing the ISP or eg. Digtal Ocean can do about. 

     

    No idea why Netgear is still ignoring the many reports ....

    SonofSouthie wrote:

    This one was the most recent, and the IP address is Comcast in Burlington, VT. Comcast security has been notified.

     

    This is your own router public IPv4 address 8-), isn't it?

     

    Or it's one of your virtual neighbours operating e.g. a Windows system, without using a NAT router ....