NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
Java_man
Jun 28, 2022Aspirant
R7000 DHCP question
I checked my R7000 log this morning and saw this: "[LAN access from remote] from 192.144.226.157:26559 to 192.168.1.2:80, Tuesday, Jun 28,2022 03:33:38" Reading through the logs I see multiple e...
FURRYe38
Jun 28, 2022Guru - Experienced User
Do a who is lookup on 192.144.226.157
What FW version is currently loaded?
What is the Mfr and model# of the Internet Service Providers modem/ONT the NG router is connected too?
- Java_manJun 28, 2022Aspirant
Thanks for the reply.
Netgear FW: V1.0.9.88_10.2.88
I looked up a couple of the IPs and they were an ISP in England - pptechnology.
Modem: Motorola Surfboard SB6120 connected to Comcast.
Also noticed they're all connecting to 192.168.1.2:80 (port 80 - the HTTP port).
- Java_manJun 28, 2022Aspirant
Gotta step out for a couple hours. I'll check in when I get back.
Thanks again.
- Java_manJun 28, 2022Aspirant
I did a little more digging in the logs. Here are a few examples:
[LAN access from remote] from 2.57.122.209:17773 to 192.168.1.2:80, Monday, Jun 27,2022 07:37:33 PPTECHNOLOGY LIMITED
[LAN access from remote] from 185.196.220.70:50551 to 192.168.1.2:80, Monday, Jun 27,2022 07:10:34 = HOSTLICK - Germany (AbuseIPDB: This IP was reported 1,076 times. Confidence of Abuse is 12%)
[LAN access from remote] from 221.176.116.78:20647 to 192.168.1.2:80, Monday, Jun 27,2022 07:09:36 = China Mobile Communications Corporation - ISP (AbuseIPDB: This IP was reported 663 times. Confidence of Abuse is 100%)
[LAN access from remote] from 154.89.5.87:58914 to 192.168.1.2:80, Monday, Jun 27,2022 06:39:43 = AgotoZ HK Limited (AbuseIPDB: This IP was reported 1,132 times. Confidence of Abuse is 100%)
[LAN access from remote] from 128.1.248.46:18057 to 192.168.1.2:80, Monday, Jun 27,2022 06:35:25 = Zenlayer Inc (AbuseIPDB: This IP was reported 14,921 times. Confidence of Abuse is 100%)
- FURRYe38Jun 28, 2022Guru - Experienced User
Hmmm...
- FURRYe38Jun 28, 2022Guru - Experienced User
Would be curious to see what happens if you set the default DHCP IP address range to 192.168.1.100 to.200.
Has a factory reset and setup from scratch been performed since you updated FW?
Something would be using .2 I believe. What browser are you using? Try MS Edge or Firefox and see what's seen in Connected Devices.