NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
SonofSouthie
Jul 20, 2026Aspirant
Getting Bombed With DDos Attacks
Since switching to a CAX30 from a C7000v2 a month ago, as noted in the subject headline, Norton has blocked them effectively. This one was the most recent, and the IP address is Comcast in Burlington...
- Jul 20, 2026
Thanks. As FURRYe38 pointed out, it is not Norton that is detecting these "attacks". Netgear routers do not accept connection attempts unless the owner has specifically defined ports to "forward" to specific devices on the local network.
The CAX30 has a feature that can make entries in the router log file when its software "detects" what it considers to be an "attack". On my RBR50 there is an option:
This option controls whether these events are recorded in the log. (It does not affect whether the router accepts connections or not).
Several users have posted recently that when they replace an older "R-series" Netgear router with a newer model, the log suddenly started filling up with these "attacks". The simple fact is that any device connected to the internet will attract connection attempts. They cannot be stopped. (Just as a mailbox will receive "junk mail" and a telephone will receive marketing calls.) The R7000 did not fill up the log file with these reports, and the CAX30 does. Your choice is whether to look at them or not.
schumaku
Jul 21, 2026Guru - Experienced User
FURRYe38 wrote:CAX30 is just reporting what's happening.
Typical false Netgear home-made positive of return traffic due to a wonky consumer router implementation.
Its about retrun traffic used form your own honme network, devices, computers, ... accessing whatver cloud or Web services , hosted on Digital Ocean.
Issue exists for virtually decades, the same decades old code is re-used on all router generations. Nothing the ISP or eg. Digtal Ocean can do about.
No idea why Netgear is still ignoring the many reports ....
SonofSouthie wrote:This one was the most recent, and the IP address is Comcast in Burlington, VT. Comcast security has been notified.
This is your own router public IPv4 address 8-), isn't it?
Or it's one of your virtual neighbours operating e.g. a Windows system, without using a NAT router ....