NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

So_tired's avatar
Jul 25, 2025
Solved

TCP SYN Flooding on RAX54v2 Router, Please help!

Hello all, i REALLY need help with stopping massive TCP SYN Floods to my home router.   What has happened thus far:   I got this router about 2 months ago ,(upgrading from a very old TP-link whic...
  • FURRYe38's avatar
    FURRYe38
    Aug 06, 2025

    OK so updated my RAX50v2 to recent FW version. 
    Factory reset and setup from scratch. 

    CAX80 in modem mode.

    PE is enabled by default. Testing with it enabled and disabled:

    PE Enabled:

     

    PE Disabled:

    I Noticed that the testing site was being reported as flooding the logs:

    [admin login] from source 192.168.1.2, Wednesday, Aug 06, 2025 15:39:37
    [admin login] from source 192.168.1.2, Wednesday, Aug 06, 2025 15:39:33
    [DoS attack: TCP SYN Flood] from source 4.79.142.206,port 45743 Wednesday, Aug 06, 2025 15:39:03

     

    After I logged in at 15:39 and disabled PE and re-tested again after that, logs didn't report any flooding from the test site. 

     

    I recommend that after you disable PE and re-test, have your ISP give you a new WAN IP address as I presume some nefarious items may have a target for that WAN IP address. Once you have PE disabled and a new WAN IP address, I'm hoping you shouldn't see issues continue.