NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

Sandibear764's avatar
Sandibear764
Aspirant
Feb 23, 2016

Security issues with C6300 Cable Modem

I have received numerous DoS ICMP Flood attacks through my C6300 Cable Modem. I have tried changing passwords, SSID Name, factory resets. Still I am having security issues.!Comcast has suggested that to fix the problem I would need to replace the modem. Is there a way to secure the modem short of purchasing an entirely new modem?

10 Replies

  • DarrenM's avatar
    DarrenM
    Sr. NETGEAR Moderator

    Hello Sandibear764

     

    Typically those attacks are when they have your Ip address does the log say what Ip these attacks are coming from?

     

    DarrenM

  • Hi Darren, thanks for responding. Yes, the event log listed 4 different IP addresses as sources. They are: 193.238.98.90; 185.94.111.1; 195.251.255.69; 203.178.148.19; and 206.117.25.90. I received multiple attacks from at least two of these IP addresses.
    • DarrenM's avatar
      DarrenM
      Sr. NETGEAR Moderator

      Sandibear764

       

      I sent you a private message about your post.

       

      DarrenM

      • birdm321's avatar
        birdm321
        Aspirant

        I'm having a similar issue but the source is "fe80:0000:0000:0000:0214:f1ff:fee8:7fe2".  The attack is occurring multiple times a day.  How can I stop this?

  • Thanks Darren, I got your message. I'm baffled by this information and how they connected with me. Anyway, thank you for all of your help. Now time to put things back to right.
  • Hello,

     

    I am seeing the same issue as OP.

    I have had my ISP come out and test my lines and no line noise, but my speeds are dropping.

    Seeing lot's of IP's listed in the logs.

    Please help!

    • DarrenM's avatar
      DarrenM
      Sr. NETGEAR Moderator

      Hello jpoorboy

       

      Can you post the logs might be able to help.

       

      DarrenM

      • jpoorboy's avatar
        jpoorboy
        Aspirant

        Hello Darren.

         

        Sorry for the delay.

        I changed my IP to 0.0.0.0 in the log snipit I have provided below.

         

        DescriptionCountLast OccurrenceTargetSource
        [DoS attack] ICMP Flood from 219.144.128.591Wednesday, 26 Jul 2017 16:07:440.0.0.0219.144.128.59
        [DoS attack] ICMP Flood from 54.94.201.101Wednesday, 26 Jul 2017 13:57:110.0.0.0

        54.94.201.10