NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
StagByTriumph
Apr 07, 2023Aspirant
Nighthawk X6 AC3000 Tri-Band WiFi Router Model R7900
So my AV's have been bugging me to update my Router FW. Win11, HW Version R7900, updated to FW Version V1.0.4.46_10.0.53 GUI Language Version V1.0.4.42_2.1.44.1 So I decided, heck mayb...
StagByTriumph
Apr 08, 2023Aspirant
Without the rant:
Has any other users had the problem when using a PC running Win11 (last year I was running Windows10 with the same problem),
HW Version R7900, updated to
FW Version V1.0.4.46_10.0.53
GUI Language Version V1.0.4.42_2.1.44.1
Outlook would no longer send/receive emails. Send/Receive ops fail with Send/Receive Error - "cannot connect". Also, after the upgrade the latency, measured using pings to the server went from less than 10 ms to more than 2 seconds.
So I flashed back to the previous FW version
Firmware Version V1.0.4.38_10.0.50
GUI Language Version V1.0.4.38_2.1.44.1
for my router an voila, instant emails and no delay in any internet. I'm thankful that at least Netgear gives the ability to downgrade.
The only change is the FW as stated, nothing else.
Ideas? I doubt the later R7900 lettered models FW can be used.
FWIW, the DDoS were caught and blocked by Snort on my Ubuntu PC monitoring my network .
Here is what the router log picked up: [DoS attack: FIN Scan] attack packets in last 20 sec from ip [34.117.223.223], Friday, Apr 07,2023 10:56:56
I cannot send a note to Tech Support I need to subscribe for a support call and pay a fee, this unit is no longer supported, and that money would be better spent on a new updated router.
michaelkenward
Apr 08, 2023Guru - Experienced User
StagByTriumph wrote:
FWIW, the DDoS were caught and blocked by Snort on my Ubuntu PC monitoring my network .
Here is what the router log picked up: [DoS attack: FIN Scan] attack packets in last 20 sec from ip [34.117.223.223], Friday, Apr 07,2023 10:56:56
That is a Google IP address.
This is a useful tool for reducing blood pressure and baseless paranoia.
IPNetInfo: Retrieve IP Address Information from WHOIS servers
As to this:
I cannot send a note to Tech Support I need to subscribe for a support call and pay a fee, this unit is no longer supported, and that money would be better spent on a new updated router.
One recent user said they had success using the "chat" facility at the boot on the support pages.
- StagByTriumphApr 14, 2023Aspirant
Sooooo, have you never used Metasploit to phake or spoof a URL or IPV4 address? That is literally childsplay for a hacker and step #1 for any deployed DDoS. I highly doubt the DoS is actually originating from Google.
Like you state in your reply, the log files are full of garbage. Why is there no "actionable intelligence" at the point of monitoring? There is IDS and then there is IPS. IDS is simply monitoring with no action, no alarmiing, no interaction with any other Intrusion Protection System or software, all of which the general user public has zero understanding or concepts and information communication systems must be designed with security capabilities, which that is ISO/IEC2700x combined with Consumer Data Protection laws in many countries.
I'll reach out to Tech Support but I'll bet they tell me all the standard scripts: Reset the router, power off the router, reset the gateway, disconect all attached devices release and reset all Netstat's, pay for Armor, reload the FW, replace the router.
- FURRYe38Apr 14, 2023Guru - Experienced User
What Firmware version is currently loaded?
What is the Mfr and model# of the Internet Service Providers modem/ONT the NG router is connected too?
Be sure your using a good quality LAN cable between the modem and router. CAT6 is recommended.Is outlook the only app not working to connect to send and get emails?
Does this happen on other devices?