NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

SonofSouthie's avatar
SonofSouthie
Aspirant
Jul 20, 2026
Solved

Getting Bombed With DDos Attacks

Since switching to a CAX30 from a C7000v2 a month ago, as noted in the subject headline, Norton has blocked them effectively. This one was the most recent, and the IP address is Comcast in Burlington...
  • HappyCat's avatar
    Jul 20, 2026

    Thanks.  As FURRYe38​ pointed out, it is not Norton that is detecting these "attacks".    Netgear routers do not accept connection attempts unless the owner has specifically defined ports to "forward" to specific devices on the local network.

     

    The CAX30 has a feature that can make entries in the router log file when its software "detects" what it considers to be an "attack".  On my RBR50 there is an option:

    This option controls whether these events are recorded in the log.  (It does not affect whether the router accepts connections or not).

     

    Several users have posted recently that when they replace an older "R-series" Netgear router with a newer model, the log suddenly started filling up with these "attacks".  The simple fact is that any device connected to the internet will attract connection attempts.  They cannot be stopped.  (Just as a mailbox will receive "junk mail" and a telephone will receive marketing calls.)  The R7000 did not fill up the log file with these reports, and the CAX30 does.  Your choice is whether to look at them or not.