NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
stevieflower
Feb 06, 2020Tutor
Nighthawk R7000 needs frequent reboots
My Nighthawk R7000 -AC1900 router needs to be frequently rebooted. This just started about 2 weeks ago. It was working perfectly. We bought it less than 6 months ago. It might connect to the intere...
- Jun 08, 2021
Running: V1.0.11.116_10.2.100
First, Sorry that this got to long. Please feel free to ignore and not read the whole thing.
I just wanted to relay my experience and how I have the router behaving very well now.
________________________________________________________________________
So I have been plagued with this stupid problem to the point of where I started to look for a different router.
But I'm holding off because I seem to have the router cooperating a lot more by doing a couple of things every day or two, that seem to keep it operating just fine now.
I haven't HAD TO reboot it in a couple of weeks or so! THAT'S PROGRESS!
So first, let me say, I think that ONE of the major problems with this router and its firmware versions, is that it does not handle massive traffic very well, EVEN THOUGHT IT'S A 'GAMING" router.
For my gaming server (which I no longer run or bother with), I had a bunch of ports forwarded to my server's static IP.
Being that these particular ports are well known for the environment I was running, there were constant attacks by :Russia
China
and a few other countries where reporting bad actors was useless.
At one point, so that I wouldn't have to totally remove all the redirects, I just put in a fake IP that went no where on my network, so that any attacks to any of those port ranges would just go to that fake IP.
I also set up huge ranges to redirect attacks to there as well...
THAT WAS A MISTAKE!!!! That's because the router would STILL try to process the requests rather than just ignoring them.
I would notice my entire network starting to grind to a halt , so I'd check the logs and see hundreds of attacks, trying to get into my server. From Remote Desktop attempts to DoS attacks to port hammering, etc.
I'd have to reboot my router and the modem that connects me to my ISP.
Doing so would get me a new external IP as well as clear the cache in the router.
I would also clear the logs, apply and refresh to clean that up.
Sometimes, I couldn't even log into the router and I would have to power cycle it.
I still have some ports open for my security cameras so that I can access away from home.
But with that, I still had the router choke up every couple of days.
I finally decided to REMOVE ALL PORT FORWARDING except for my cameras. Those are vital.
Well that settled things down A LOT!
However, then I would see those same countries trying to access my cameras.
So for those, I tightened up their passwords. At least it won't be easy for those BOZOS to monitor my cams.
But still, the router was not stable. Sure, it was a lot more stable, but I still had to reboot every few days!
To troubleshoot this problem, I have a Command Prompt constantly pinning google.com -t.
When the router would start to get wonky, I'd see packets dropping from the ping.... INTERESTING.
Sure enough, in the logs, I would see attacks, including still, DoS attacks.
But something still didn't seem right.
So then, I added another command prompt window and constantly piinged the router's internal IP.
I wanted to see if pinging outside my network to the internet would fail, but internal pinging was ok.
Sometimes, this was the case ,but other times, more often, when one would start dropping packets, so would the other! HMMMMM
So then, I powered up my laboratory computer, which sits right beside the router and is wired directly into it. This computer does NOT go through anything else, no switches, nothing.
I also ran a command prompt, pinging the router as well.
Now, with 3 pings being monitored, I could get a better visual on where the breakdown is happening.
So now here is where I found what is in fact one of the biggest problems with this dammed router.
THE LOGS! Yes! THE FREAK'N LOGS!
What I discovered that as the log file increased in size, is when the router would start to get wonky!
I could see dropped packets on the external ping, then drops on this machine that pings the router (but it goes through switches). But sometimes, the Lab computer wasn't seeing drops!
But then, I'd start seeing drops on the connected Lab computer.
I started monitoring the logs closer but nothing unexpected was seen.
I did notice, however, that the drops were right around the time that the attackers were trying to get connected to the ports that I did have open.
But at other times, even with that, there was no issues.
I got into the habit of clearing the logs so I would get a clear picture each time.
It's then that I noticed, when I cleared the logs, within seconds, the dropping of packets stopped and the router settled back down!
I've seen this kind of file corruption in older software, but I would have thought that in 2020/2021 there would be much better routines to keep caching in check.
So, very long story short,- remove any port forwarding that you do not NEED
- do not set up huge ranges of ports to forward to a fake IP (if you don't forward ports, the router will just ignore requests to ports not listed)
- clear the log daily (at least to confirm if this solves the problem).
Retired_Member
Mar 30, 2021You mention a version that ends in .44.
Is it possible that you mean, .42?
I checked the downloads (prev. versions) and I'm not seeing .44. I do see and have downloaded ver .42.
Please clarify also, if possible, could you please confirm how things are working now?
I had to update my R7000 to the latest version due to so many attacks right now coming from Russia.
I also have to reboot this router as well as my internet Modem as that gets a new, external IP each time. That helps.
But today, I had to reboot the R7000 becasue even with a new external IP, the router became very unstable, dropping all connections, both to the internet and my internal network.
After reboot, as usual, it's fine.
That new Armor thing not only doesn't seem to really do anything, but seems to just be a money grab.
Any time that I go into the Armor app, it always has 0 Threats Blocked!
It's NOT blockint those DoS attacks at all.
As for "Vulnerabilities" goes, it always says that there are 6 and all of those are my security cameras, which ARE secure. LOL
It also complains, "Device HiJack vulnerability detected" and then suggests software update. But at no time does it go into any detail at all about WHAT is the issue or WHERE the issue is SUPPOSEDLY being detected.
VERY poor implementation of this Armor thing.
Clearly, this Armor thing is crap.
I will be disabling it.
So I might go back to .42 as many report it as stable.
Right now, I'm on
V1.0.11.116_10.2.100
antinode
Mar 30, 2021Guru
> You mention a version that ends in .44.
> Is it possible that you mean, .42?
"You"?
Does "V1.0.9.42_10.2.44" end in ".42" or ".44"? How much of it does?
> Right now, I'm on
> V1.0.11.116_10.2.100
In what does that end? ".116"? ".100"?
- BlondieSLMar 30, 2021Guide
Sorry, antinode. I don't know what happened there. This website is giving me a very hard time. If I do a google search which brings me to this forum, it complains that I cannot be authenticated. Every time! I have to open a new window, go to netgear.com and login from there. Then I come back to refresh here and that works. However, I was trying to respond to mnijskens. I did click on Reply in that person's comment. So the "You" should be to " mnijskens". As for my current version, V1.0.11.116_10.2.100, that is a copy and paste right from the router's window when logged in. The actual filename of this firmware is: R7000-V1.0.11.116_10.2.100.chk. Other than that, I'm not sure what you mean. :) As for the .42 version, the filename I have here is: R7000-V1.0.9.42_10.2.44.chk. I will mention that with the version I updated to, V1.0.11.116_10.2.100, I did run into weird problems accessing my security cameras from my smart phone away from my internal network. Very odd. Some cams worked, others did not. I had to remove them then readd them to work again. At least things are working better now, but still, the issue where the router needs to be rebooted sometimes. Mind you, only once since the update a few days ago. I've also disabled Armor as it doesn't seem to actually do anything. But that's another thread. LOL I hope that answers your questions. :)
- BlondieSLMar 30, 2021GuideSorry, the "you" was referring to another poster. I'm not sure what happened there. As for the version name, it is exactly as posted. The actual filename is the same as presented.