NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
Pete10p
Feb 22, 2018Aspirant
ReadyNAS 102 sending to 64.233.167.109
I have two ReadyNas 102's running 6.9.2 firmware. My home LAN is setup to drop all traffic from and to the internet to be dropped. According to my router’s logs, both 102's are continually at...
mdgm-ntgr
Feb 23, 2018NETGEAR Employee Retired
Can you send me your logs (see the Sending Logs link in my sig)?
mdgm-ntgr
Feb 25, 2018NETGEAR Employee Retired
Looks like your system is having problems sending queued email alerts. I think that I.P. is associated with gmail.
Is your NAS behind a corporate firewall/proxy?
- Pete10pFeb 25, 2018Aspirant
My firewall is set to drop all inbound and outbound traffic from the two ReadyNas.
I have deleted the email alerts, but the router is still seeing attempts to send something from the ReadyNas. The ReadyNas log has one incidence of a failure to send an alert however the router is seeing constant outbound attempts from the ReadyNas approx. every 15 seconds.
- StephenBFeb 25, 2018Guru - Experienced User
I think mdgm-ntgr is seeing that some email alerts were queued up for transmission (likely blocked by your firewall). Turning off email alerts might not clear that queue. You could try temporarily enabling gmail email alerts again, and also enable outbound SMTP (port 465 or possibly 587, depending on whether you set it up for SSL or TLS). Then after the queue clears and you receive whatever's in the queue, you can disable the alerts in the NAS and then disable the ports in your firewall rules.
- Pete10pFeb 26, 2018Aspirant
Thanks for responding.
I’ve deleted all the email information on the ReadyNas and rebooted it and the routers just to clear everything, but the persistent outbound attempts have continued. It’s now running at one every two seconds with no break.
I’ve implement the solution of another of the community suggested which is a fixed IP address and giving the ReadyNas a none existent DNS address. This has worked.
This has at least stopped my router logs being filled by firewall denial messages.
I still have a concern that the ReadyNas has some form of background routine running attempting to send data to ?????.
I’ve switched off all the obvious routines like internet time, email alerts, anti virus etc., but something is running.
I wish Netgear would just be open about what is being sent by the ReadyNas and to who.
- Ki_Adi_MundiFeb 27, 2018NETGEAR Employee Retired
If it's the mail queue tried to connect, we can delete the things under /etc/frontview/.msmtp.queue/ when enable ssh access.
- StephenBFeb 27, 2018Guru - Experienced User
Ki_Adi_Mundi wrote:
If it's the mail queue tried to connect, we can delete the things under /etc/frontview/.msmtp.queue/ when enable ssh access.
Thanks for that tip!
- Pete10pFeb 27, 2018Aspirant
I dont know how to do that
Related Content
NETGEAR Academy
Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!