NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
yagirlchels
May 06, 2021Aspirant
CONSTANT DOS ATTACKS & DISCONNECTION
For the last two weeks, my internet has been acting up and keeps just randomly disconnecting. Only for a couple of seconds but it happens back to back all day long. Can someone help me understand whats happening. I have never had any issues before and the router was bought back in November of last year. This is what my log looks like...
| admin login] from source 0.0.0.0 | 1 | Thu May 06 14:31:10 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [DHCP IP: 192.168.0.13] to MAC address f0:18:98:a4:f6:ab | 1 | Thu May 06 14:31:08 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet connected] IP address: 73.28.71.3 | 1 | Thu May 06 14:00:01 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Time synchronized with ToD server] | 1 | Thu May 06 13:59:47 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet disconnected] | 1 | Thu May 06 13:57:52 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet connected] IP address: 73.28.71.3 | 1 | Thu May 06 13:37:50 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Time synchronized with ToD server] | 1 | Thu May 06 13:37:36 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet disconnected] | 1 | Thu May 06 13:37:05 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet connected] IP address: 73.28.71.3 | 1 | Thu May 06 13:30:01 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Time synchronized with ToD server] | 1 | Thu May 06 13:29:48 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet disconnected] | 1 | Thu May 06 13:29:18 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Thu May 06 13:20:18 2021 | 73.28.71.3:64045 | 8.8.8.8:53 |
| [DHCP IP: 192.168.0.11] to MAC address 62:18:d3:62:53:1f | 1 | Thu May 06 13:20:15 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet connected] IP address: 73.28.71.3 | 1 | Thu May 06 13:12:55 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Time synchronized with ToD server] | 1 | Thu May 06 13:12:40 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet disconnected] | 1 | Thu May 06 13:12:11 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet connected] IP address: 73.28.71.3 | 1 | Thu May 06 12:37:48 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Time synchronized with ToD server] | 1 | Thu May 06 12:37:34 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet disconnected] | 1 | Thu May 06 12:37:01 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet connected] IP address: 73.28.71.3 | 1 | Thu May 06 11:42:46 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Time synchronized with ToD server] | 1 | Thu May 06 11:42:33 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet disconnected] | 1 | Thu May 06 11:42:05 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Thu May 06 08:49:22 2021 | 73.28.71.3:53402 | 8.8.8.8:53 |
| [DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Thu May 06 08:42:54 2021 | 73.28.71.3:63872 | 8.8.8.8:53 |
| [DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Thu May 06 08:35:26 2021 | 73.28.71.3:55626 | 8.8.8.8:53 |
| [DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Thu May 06 08:19:36 2021 | 73.28.71.3:64277 | 8.8.8.8:53 |
| [Internet connected] IP address: 73.28.71.3 | 1 | Thu May 06 08:14:17 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Time synchronized with ToD server] | 1 | Thu May 06 08:14:03 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet disconnected] | 1 | Thu May 06 08:13:27 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Thu May 06 07:24:17 2021 | 73.28.71.3:56225 | 8.8.8.8:53 |
| [DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Thu May 06 06:31:20 2021 | 73.28.71.3:52103 | 8.8.8.8:53 |
| [DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Thu May 06 06:07:38 2021 | 73.28.71.3:65205 | 8.8.8.8:53 |
| [DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Thu May 06 06:03:44 2021 | 73.28.71.3:49358 | 8.8.8.8:53 |
| [DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Thu May 06 05:48:26 2021 | 73.28.71.3:51577 | 8.8.8.8:53 |
| [DHCP IP: 192.168.0.11] to MAC address 62:18:d3:62:53:1f | 1 | Thu May 06 05:48:25 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [DHCP IP: 192.168.0.11] to MAC address 62:18:d3:62:53:1f | 1 | Thu May 06 05:48:24 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet connected] IP address: 73.28.71.3 | 1 | Thu May 06 02:02:13 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Time synchronized with ToD server] | 1 | Thu May 06 02:01:58 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet disconnected] | 1 | Thu May 06 02:01:22 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [UPnP set event: DeletePortMapping] from source 192.168.0.17 | 1 | Thu May 06 01:20:59 2021 | 0.0.0.0:0 | 192.168.0.17:0 |
| [UPnP set event: GetExternalIPAddress] from source 192.168.0.17 | 1 | Thu May 06 01:20:59 2021 | 0.0.0.0:0 | 192.168.0.17:0 |
| [UPnP set event: AddPortMapping] from source 192.168.0.17 | 1 | Thu May 06 01:20:25 2021 | 0.0.0.0:0 | 192.168.0.17:0 |
| [UPnP set event: GetExternalIPAddress] from source 192.168.0.17 | 1 | Thu May 06 01:20:25 2021 | 0.0.0.0:0 | 192.168.0.17:0 |
| [DHCP IP: 192.168.0.17] to MAC address 4c:3b:df:73:81:1d | 1 | Thu May 06 01:20:25 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet connected] IP address: 73.28.71.3 | 1 | Thu May 06 00:29:59 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Time synchronized with ToD server] | 1 | Thu May 06 00:29:44 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet disconnected] | 1 | Thu May 06 00:29:12 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet connected] IP address: 73.28.71.3 | 1 | Wed May 05 23:36:08 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Time synchronized with ToD server] | 1 | Wed May 05 23:35:54 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet disconnected] | 1 | Wed May 05 23:32:53 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet connected] IP address: 73.28.71.3 | 1 | Wed May 05 22:06:22 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Time synchronized with ToD server] | 1 | Wed May 05 22:06:09 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet disconnected] | 1 | Wed May 05 22:05:42 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [DHCP IP: 192.168.0.17] to MAC address 4c:3b:df:73:81:1d | 1 | Wed May 05 22:03:01 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [DHCP IP: 192.168.0.17] to MAC address 4c:3b:df:73:81:1d | 1 | Wed May 05 22:02:30 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Wed May 05 21:34:03 2021 | 73.28.71.3:56201 | 8.8.8.8:53 |
| [DoS attack: SYN Flood] from 52.143.79.188, port 443 | 1 | Wed May 05 21:17:46 2021 | 192.168.0.17:49940 | 52.143.79.188:443 |
| [DoS attack: SYN Flood] from 52.251.11.100, port 443 | 1 | Wed May 05 21:17:36 2021 | 192.168.0.17:49883 | 52.251.11.100:443 |
| [DoS attack: SYN Flood] from 40.70.154.148, port 443 | 1 | Wed May 05 21:17:32 2021 | 192.168.0.17:49844 | 40.70.154.148:443 |
| [DoS attack: SYN Flood] from 104.94.108.9, port 443 | 1 | Wed May 05 21:17:13 2021 | 192.168.0.17:49802 | 104.94.108.9:443 |
| [UPnP set event: AddPortMapping] from source 192.168.0.17 | 1 | Wed May 05 21:17:06 2021 | 0.0.0.0:0 | 192.168.0.17:0 |
| [UPnP set event: GetExternalIPAddress] from source 192.168.0.17 | 1 | Wed May 05 21:17:06 2021 | 0.0.0.0:0 | 192.168.0.17:0 |
| [DHCP IP: 192.168.0.17] to MAC address 4c:3b:df:73:81:1d | 1 | Wed May 05 21:17:06 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Wed May 05 21:13:29 2021 | 73.28.71.3:55320 | 8.8.8.8:53 |
| [DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Wed May 05 21:06:01 2021 | 73.28.71.3:49535 | 8.8.8.8:53 |
| [DHCP IP: 192.168.0.11] to MAC address 62:18:d3:62:53:1f | 1 | Wed May 05 21:05:59 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet connected] IP address: 73.28.71.3 | 1 | Wed May 05 21:00:17 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Time synchronized with ToD server] | 1 | Wed May 05 21:00:03 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet disconnected] | 1 | Wed May 05 20:59:23 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet connected] IP address: 73.28.71.3 | 1 | Wed May 05 18:48:04 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Time synchronized with ToD server] | 1 | Wed May 05 18:47:50 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [Internet disconnected] | 1 | Wed May 05 18:47:21 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
| [DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Wed May 05 16:59:34 2021 | 73.28.71.3:55071 | 8.8.8.8:53 |
| [DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Wed May 05 16:54:07 2021 | 73.28.71.3:58335 | 8.8.8.8:53 |
| [DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Wed May 05 16:41:31 2021 | 73.28.71.3:58711 | 8.8.8.8:53 |
| [DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Wed May 05 16:36:51 2021 | 73.28.71.3:49410 | 8.8.8.8:53 |
| [DoS attack: TCP- or UDP-based Port Scan] from 8.8.4.4, port 53 | 1 | Wed May 05 16:35:20 2021 | 73.28.71.3:62235 | 8.8.4.4:53 |
| [DoS attack: SYN Flood] from 17.248.137.108, port 443 | 1 | Wed May 05 16:35:05 2021 | 192.168.0.11:64459 | 17.248.137.108:443 |
| [DoS attack: TCP- or UDP-based Port Scan] from 1.1.1.1, port 53 | 1 | Wed May 05 16:35:04 2021 | 73.28.71.3:63401 | 1.1.1.1:53 |
| [DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Wed May 05 16:34:53 2021 | 73.28.71.3:58432 | 8.8.8.8:53 |
| [DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Wed May 05 16:31:17 2021 | 73.28.71.3:57693 | 8.8.8.8:53 |
10 Replies
- DarrenMSr. NETGEAR Moderator
Have you checked the logs of the ISP modem to see if you have any T3 or T4 timeouts?
DarrenM
- carapungoAspirant
were you able to fix this issue?, what was causing it, and what was the solution?
- microchip8Master
NETGEAR is famously known for many false positives DoS attacks. Their "protection" is virtually useless. I suggest turnning off DoS protection completely off and see if you get a stable device. Myself, I've been running without DoS protection since I bought my router (3.5 years ago) and never had an issue.
- carapungoAspirant
Thanks. That's what I did this morning, and now my event log is empty, which I assume is a good thing. I have not seen any connection drops so far.
- yagirlchelsAspirant
So, I actually had to contact my ISP (xfinity) and end up getting an entirely new IP address for my router. Nothing else was working. I havent had an issue since then.
- FURRYe38Guru - Experienced User
Sounds like this was coming in from the ISP side then.
Please mark your thread as solved so others will know.
Be sure to save off a back up configuration to file for safe keeping. Saves time if a reset is needed.
https://kb.netgear.com/24231/How-do-I-back-up-the-router-configuration-settings-on-my-Nighthawk-router
Enjoy.
yagirlchels wrote:
So, I actually had to contact my ISP (xfinity) and end up getting an entirely new IP address for my router. Nothing else was working. I havent had an issue since then.