NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
SonofSouthie
Jul 20, 2026Aspirant
Getting Bombed With DDos Attacks
Since switching to a CAX30 from a C7000v2 a month ago, as noted in the subject headline, Norton has blocked them effectively. This one was the most recent, and the IP address is Comcast in Burlington, VT. Comcast security has been notified.
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 14:06:57
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 14:06:57
[DHCP IP: (192.168.1.2)] to MAC address e4:54:e8:b8:3e:4b, Jul 20 09:41:02
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 13:18:42
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 13:18:42
[DHCP IP: (192.168.1.2)] to MAC address e4:54:e8:b8:3e:4b, Jul 20 09:17:38
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 13:06:42
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 13:06:42
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 12:54:41
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 12:54:41
[DHCP IP: (192.168.1.2)] to MAC address e4:54:e8:b8:3e:4b, Jul 20 08:31:33
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 12:30:31
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 12:30:31
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 12:06:22
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 12:06:22
[DHCP IP: (192.168.1.3)] to MAC address 74:40:be:47:4f:f6, Jul 20 08:02:54
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 11:42:21
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 11:42:21
[DHCP IP: (192.168.1.2)] to MAC address e4:54:e8:b8:3e:4b, Jul 20 07:31:48
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 11:30:21
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 11:30:21
[DHCP IP: (192.168.1.5)] to MAC address e6:57:8a:e0:4d:2f, Jul 20 07:25:01
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 11:18:19
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 11:18:19
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 11:06:16
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 11:06:16
[DHCP IP: (192.168.1.2)] to MAC address e4:54:e8:b8:3e:4b, Jul 20 07:01:03
[DHCP IP: (192.168.1.2)] to MAC address e4:54:e8:b8:3e:4b, Jul 20 06:58:04
[DHCP IP: (192.168.1.2)] to MAC address e4:54:e8:b8:3e:4b, Jul 20 06:57:58
[DHCP IP: (192.168.1.2)] to MAC address e4:54:e8:b8:3e:4b, Jul 20 06:48:11
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 10:42:11
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 10:42:11
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 10:30:11
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 10:30:11
[DHCP IP: (192.168.1.3)] to MAC address 74:40:be:47:4f:f6, Jul 20 06:29:00
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 10:18:11
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 10:18:11
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 09:54:01
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 09:54:01
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 09:30:01
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 09:30:01
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 09:05:52
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 09:05:52
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 08:53:51
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 08:53:51
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 08:29:51
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 08:29:51
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 07:53:41
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 07:53:41
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 07:41:41
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 07:41:41
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 07:29:41
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 07:29:41
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 06:53:41
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 06:53:41
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 06:17:41
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 06:17:41
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 05:53:41
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 05:53:41
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 05:41:41
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 05:41:41
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 05:17:41
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 05:17:41
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 04:17:41
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 04:17:41
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 03:17:41
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 03:17:41
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 02:53:41
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 02:53:41
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 02:29:41
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 02:29:41
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 02:17:41
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 02:17:41
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 01:17:41
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 01:17:41
[DHCP IP: (192.168.1.3)] to MAC address 74:40:be:47:4f:f6, Jul 19 21:07:41
[DHCP IP: (192.168.1.2)] to MAC address e4:54:e8:b8:3e:4b, Jul 19 20:38:43
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 20 00:18:21
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 20 00:18:21
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 19 23:59:21
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 19 23:59:21
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 19 23:51:12
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 19 23:44:12
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 19 23:44:12
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 138, Jul 19 23:38:09
[DoS attack: LAND Attack] source: 71.234.194.89, port: 138, Jul 19 23:38:09
[DHCP IP: (192.168.1.3)] to MAC address 74:40:be:47:4f:f6, Jul 19 19:29:11
[DoS attack: FW.WANATTACK DROP] source: 71.234.194.89, port: 137, Jul 19 23:28:24
ioned attacks every day(I check security logs).
8 Replies
- FURRYe38Guru - Experienced User
Will need to keep in contact with the ISP for that IP address.
CAX30 is just reporting what's happening. Hopefully the ISP can figure it out.
- SonofSouthieAspirant
Thx. I keep getting some attacks from different IP addresses, check the addresses via iplocation.com, and they all belong to Digital Ocean. I contact them and get a reply, "We'll tell our customers to stop"
- FURRYe38Guru - Experienced User
Might ask the ISP to change the WAN IP address as well.
The firewall on the CAX is working. Just the logs are reporting what is happening is all.
SonofSouthie wrote:
Thx. I keep getting some attacks from different IP addresses, check the addresses via iplocation.com, and they all belong to Digital Ocean. I contact them and get a reply, "We'll tell our customers to stop"
- HappyCatApprentice
Is that list of "attacks" from:
- The CAX30 log file, or
- From Norton on a PC?
- SonofSouthieAspirant
CAX log.
- HappyCatApprentice
Thanks. As FURRYe38 pointed out, it is not Norton that is detecting these "attacks". Netgear routers do not accept connection attempts unless the owner has specifically defined ports to "forward" to specific devices on the local network.
The CAX30 has a feature that can make entries in the router log file when its software "detects" what it considers to be an "attack". On my RBR50 there is an option:
This option controls whether these events are recorded in the log. (It does not affect whether the router accepts connections or not).
Several users have posted recently that when they replace an older "R-series" Netgear router with a newer model, the log suddenly started filling up with these "attacks". The simple fact is that any device connected to the internet will attract connection attempts. They cannot be stopped. (Just as a mailbox will receive "junk mail" and a telephone will receive marketing calls.) The R7000 did not fill up the log file with these reports, and the CAX30 does. Your choice is whether to look at them or not.
- HappyCatApprentice
sorry about the typo. should be "C7000" rather than "R7000".
- SonofSouthieAspirant
Thanks to all who replied. ;^)