NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
marteeleigh
Oct 05, 2021Tutor
DoS attacks (ACK & STORM) - causing DNS issues and connection drops?
This is a continuation of issues here: For the last month+, DNS issues and dropped Wi-Fi (now using R7000P) Netgear support emailed me back and said I have a DoS attack. This is part of the info...
michaelkenward
Oct 05, 2021Guru - Experienced User
marteeleigh wrote:
Apologies. I am failing at multitasking (also speaking with Sparklight support right now). My modem is Motorola MB8611.
Straightforward modem with no router to get in the way.
MB8611 Ultra-Fast DOCSIS 3.1 Cable Modem with 2.5Gb Ethernet - Motorola
marteeleigh wrote:
Thanks for looking at those IP addresses! Can you tell me what harmless means, though, in this context? Like it's enough to be a disruption but otherwise not harmful?
They are harmless because they are from recognised ISPs and Internet services. They will not be attacking you.
Other things that can feature in those logs are Google, Amazon and other familiar names.
They show up in your logs because the Netgear firmware is doing its usual "false positive" thing, an issue that comes up here often.
Check this search for dos attacks.
The only harm those entries will do to your network is if the logging uses up processor power and slows down the router's management of other tasks.
If you see that sort of behaviour you can safely disable the logging process. Some people even disable the protection process itself, again with no ill effect.
To me this suggests that you ISP is talking rubbish. There are no DDS attacks on your network to prevent it from getting at your modem.
So following the suggestion from FURRYe38 would be a good way of smoking them out.
Quite who told you that from Netgear escapes me. But I was not in on your conversation with them.
marteeleigh
Oct 05, 2021Tutor
Your explanation was thoughtful and very well recieved. Thank you for taking the time to respond in such a manner. How you explained it makes sense. I feel silly for making this an issue. It all started with DNS issues and dropped Wi-Fi, and then the Netgear tech mentioned DoS attacks, so down the rabbit hole I went.
For now (tomorrow), I will proceed with the replacement modem (although that likely won't help except to provide new IP and MAC addresses), if that's even necessary at this point. This new TP-Link router has not dropped connection since I set it up yesterday, so maybe I just stick with TP-Link and revisit the Nighthawk when/if TP-Link goes out.
If there are suggestions for different cable modems, I am all ears. I wish I could say the modem was the issue, but the DNS issues occured last month when I had a DSL modem (CenturyLink) alongside a an AC1750 Nighthawk.
Thanks again to you both, michaelkenward and FURRYe38 <3. I appreciate you sticking with me through often incoherrant questions.
- FURRYe38Oct 05, 2021Guru - Experienced User
Make sure the ISP service, signal and signal line is in good working order first. Putting a different modem on may not fix the issue.
Have the ISP check the signal and line quality UP to the modem. Be sure the ISP provisions the modem correctly.
Be sure there are no coax cable line splitters in the between the modem and ISP service box.
Be sure your using good quality RG6 coax cable up to the modem.Have the ISP check the modems connection status page as well. There is signal information there that you can give them to help ensure the modem and signal is to spec.