Orbi WiFi 7 RBE973
Reply

C6300 Logs > DoS Attack

griffin9
Aspirant

C6300 Logs > DoS Attack

Hello,

 

I have been having significant performance issues lately with my internet throughout the house, both wireless and wired. I finally contacted my ISP, after seeing random "[DoS Attack]" listings in the logs and realizing they often coincide with complete disconnection from the internet. (My issue is both slow internet and at times, no internet.) The tech assured me nothing looks wrong on their end, and the DoS Attacks weren't something to be worried about.

 

That's fine, but nothing has improved for me, and I've noticed an increase in them now. I hope someone in the community can point me to a solution. Thank you in advance!

 

Below is what I hope is all relavent information:

Hardware Version: 3.0

Firmare Version: 1.02.21

 

Logs for the past ~3 days:

Description 	Count 	Last Occurrence 	Target 	Source
[DHCP IP: (192.168.0.40)] to MAC address 02:0f:b5:11:c3:e3 	1	Thursday, 09 Feb 2017 12:02:29	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.41)] to MAC address 02:0f:b5:0a:3e:93 	2	Thursday, 09 Feb 2017 11:53:52	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	1	Thursday, 09 Feb 2017 11:53:23	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.37)] to MAC address ac:37:43:4a:56:a4 	1	Thursday, 09 Feb 2017 11:53:12	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.38)] to MAC address 02:0f:b5:b2:a6:b2 	1	Thursday, 09 Feb 2017 11:53:06	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.39)] to MAC address 02:0f:b5:4a:56:a4 	9	Thursday, 09 Feb 2017 10:59:14	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	1	Thursday, 09 Feb 2017 10:30:25	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.39)] to MAC address 02:0f:b5:4a:56:a4 	11	Thursday, 09 Feb 2017 10:27:19	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.26)] to MAC address b0:e8:92:0c:77:73 	1	Thursday, 09 Feb 2017 09:37:10	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.39)] to MAC address 02:0f:b5:4a:56:a4 	2	Thursday, 09 Feb 2017 09:32:26	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.21)] to MAC address 44:8a:5b:5e:a7:6f 	1	Thursday, 09 Feb 2017 09:30:14	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.39)] to MAC address 02:0f:b5:4a:56:a4 	3	Thursday, 09 Feb 2017 09:28:21	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	3	Thursday, 09 Feb 2017 09:17:50	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.39)] to MAC address 02:0f:b5:4a:56:a4 	2	Thursday, 09 Feb 2017 09:09:06	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	1	Thursday, 09 Feb 2017 09:05:57	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.39)] to MAC address 02:0f:b5:4a:56:a4 	1	Thursday, 09 Feb 2017 09:05:07	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	1	Thursday, 09 Feb 2017 09:04:06	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.39)] to MAC address 02:0f:b5:4a:56:a4 	1	Thursday, 09 Feb 2017 09:01:29	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	1	Thursday, 09 Feb 2017 09:00:32	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.39)] to MAC address 02:0f:b5:4a:56:a4 	3	Thursday, 09 Feb 2017 08:59:52	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	1	Thursday, 09 Feb 2017 08:53:15	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.39)] to MAC address 02:0f:b5:4a:56:a4 	3	Thursday, 09 Feb 2017 08:51:38	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	1	Thursday, 09 Feb 2017 08:41:51	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.39)] to MAC address 02:0f:b5:4a:56:a4 	3	Thursday, 09 Feb 2017 08:41:23	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.41)] to MAC address 02:0f:b5:0a:3e:93 	1	Thursday, 09 Feb 2017 08:35:44	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.39)] to MAC address 02:0f:b5:4a:56:a4 	1	Thursday, 09 Feb 2017 08:33:50	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	1	Thursday, 09 Feb 2017 08:33:49	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.39)] to MAC address 02:0f:b5:4a:56:a4 	7	Thursday, 09 Feb 2017 08:31:32	0.0.0.0	0.0.0.0
[DoS attack] ICMP Flood from 64.137.220.2 	1	Thursday, 09 Feb 2017 08:05:03	[My IP]	64.137.220.2
[DHCP IP: (192.168.0.39)] to MAC address 02:0f:b5:4a:56:a4 	1	Thursday, 09 Feb 2017 07:55:19	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.37)] to MAC address ac:37:43:4a:56:a4 	1	Thursday, 09 Feb 2017 07:51:38	0.0.0.0	0.0.0.0
[DoS attack] ICMP Flood from 46.72.87.34 	1	Thursday, 09 Feb 2017 06:45:30	[My IP]	46.72.87.34
[DoS attack] ICMP Flood from 96.93.253.73 	1	Thursday, 09 Feb 2017 05:24:34	[My IP]	96.93.253.73
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	1	Thursday, 09 Feb 2017 05:09:21	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.22)] to MAC address 98:fe:94:11:c3:e3 	1	Thursday, 09 Feb 2017 04:53:03	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	1	Thursday, 09 Feb 2017 03:18:24	0.0.0.0	0.0.0.0
[DoS attack] ICMP Flood from 72.12.209.146 	1	Thursday, 09 Feb 2017 02:29:15	[My IP]	72.12.209.146
[DoS attack] ICMP Flood from 169.56.71.41 	1	Thursday, 09 Feb 2017 02:26:04	[My IP]	169.56.71.41
[DoS attack] ICMP Flood from 169.56.71.34 	1	Thursday, 09 Feb 2017 01:52:08	[My IP]	169.56.71.34
[DoS attack] ICMP Flood from 169.56.71.41 	1	Thursday, 09 Feb 2017 00:39:24	[My IP]	169.56.71.41
[DoS attack] ICMP Flood from 169.56.71.55 	1	Wednesday, 08 Feb 2017 23:23:33	[My IP]	169.56.71.55
[DoS attack] ICMP Flood from 61.134.39.90 	1	Wednesday, 08 Feb 2017 23:20:46	[My IP]	61.134.39.90
[DHCP IP: (192.168.0.26)] to MAC address b0:e8:92:0c:77:73 	1	Wednesday, 08 Feb 2017 21:37:11	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	2	Wednesday, 08 Feb 2017 21:11:56	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.41)] to MAC address 02:0f:b5:0a:3e:93 	2	Wednesday, 08 Feb 2017 21:04:32	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.38)] to MAC address 02:0f:b5:b2:a6:b2 	1	Wednesday, 08 Feb 2017 21:03:00	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	1	Wednesday, 08 Feb 2017 20:03:04	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.21)] to MAC address 44:8a:5b:5e:a7:6f 	1	Wednesday, 08 Feb 2017 19:54:09	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.37)] to MAC address ac:37:43:4a:56:a4 	1	Wednesday, 08 Feb 2017 19:51:38	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.22)] to MAC address 98:fe:94:11:c3:e3 	1	Wednesday, 08 Feb 2017 19:39:37	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	1	Wednesday, 08 Feb 2017 19:33:40	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.38)] to MAC address 02:0f:b5:b2:a6:b2 	1	Wednesday, 08 Feb 2017 18:04:53	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.22)] to MAC address 98:fe:94:11:c3:e3 	1	Wednesday, 08 Feb 2017 14:03:45	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.41)] to MAC address 02:0f:b5:0a:3e:93 	1	Wednesday, 08 Feb 2017 13:19:16	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	13	Wednesday, 08 Feb 2017 13:06:38	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.26)] to MAC address b0:e8:92:0c:77:73 	1	Wednesday, 08 Feb 2017 09:37:12	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	20	Wednesday, 08 Feb 2017 09:26:02	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.21)] to MAC address 44:8a:5b:5e:a7:6f 	1	Wednesday, 08 Feb 2017 07:56:25	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.45)] to MAC address 02:0f:b5:86:ba:dc 	2	Wednesday, 08 Feb 2017 07:34:38	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	6	Wednesday, 08 Feb 2017 07:10:15	0.0.0.0	0.0.0.0
[DoS attack] ICMP Flood from 213.172.51.50 	1	Wednesday, 08 Feb 2017 06:12:29	[My IP]	213.172.51.50
[DHCP IP: (192.168.0.37)] to MAC address ac:37:43:4a:56:a4 	1	Wednesday, 08 Feb 2017 05:28:02	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	23	Wednesday, 08 Feb 2017 04:51:34	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.22)] to MAC address 98:fe:94:11:c3:e3 	1	Wednesday, 08 Feb 2017 02:02:45	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	1	Wednesday, 08 Feb 2017 02:01:39	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.22)] to MAC address 98:fe:94:11:c3:e3 	1	Wednesday, 08 Feb 2017 01:55:40	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.40)] to MAC address 02:0f:b5:11:c3:e3 	1	Wednesday, 08 Feb 2017 01:49:20	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	1	Wednesday, 08 Feb 2017 01:48:43	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.41)] to MAC address 02:0f:b5:0a:3e:93 	2	Wednesday, 08 Feb 2017 01:48:03	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	2	Wednesday, 08 Feb 2017 01:39:30	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.38)] to MAC address 02:0f:b5:b2:a6:b2 	1	Wednesday, 08 Feb 2017 01:34:52	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.22)] to MAC address 98:fe:94:11:c3:e3 	1	Wednesday, 08 Feb 2017 01:33:30	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	4	Wednesday, 08 Feb 2017 01:30:54	0.0.0.0	0.0.0.0
[DoS attack] ICMP Flood from 42.92.135.197 	1	Wednesday, 08 Feb 2017 01:03:02	[My IP]	42.92.135.197
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	3	Wednesday, 08 Feb 2017 01:01:04	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.38)] to MAC address 02:0f:b5:b2:a6:b2 	1	Wednesday, 08 Feb 2017 00:38:20	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	3	Wednesday, 08 Feb 2017 00:07:22	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.38)] to MAC address 02:0f:b5:b2:a6:b2 	2	Wednesday, 08 Feb 2017 00:03:00	0.0.0.0	0.0.0.0
[DoS attack] AIF:Dropped INPUT packet: PROTO:TCP SPT:58645 DPT:23	1	Tuesday, 07 Feb 2017 23:49:59	[My IP]	220.133.202.156
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	3	Tuesday, 07 Feb 2017 23:40:33	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.38)] to MAC address 02:0f:b5:b2:a6:b2 	7	Tuesday, 07 Feb 2017 23:30:55	0.0.0.0	0.0.0.0
[DoS attack] ICMP Flood from 185.94.111.1 	1	Tuesday, 07 Feb 2017 23:09:44	[My IP]	185.94.111.1
[DHCP IP: (192.168.0.38)] to MAC address 02:0f:b5:b2:a6:b2 	2	Tuesday, 07 Feb 2017 23:08:38	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.40)] to MAC address 02:0f:b5:11:c3:e3 	2	Tuesday, 07 Feb 2017 22:38:31	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	1	Tuesday, 07 Feb 2017 22:23:27	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.40)] to MAC address 02:0f:b5:11:c3:e3 	1	Tuesday, 07 Feb 2017 22:23:09	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.38)] to MAC address 02:0f:b5:b2:a6:b2 	2	Tuesday, 07 Feb 2017 22:23:07	0.0.0.0	0.0.0.0
[DoS attack] ICMP Flood from 169.56.71.47 	1	Tuesday, 07 Feb 2017 21:40:27	[My IP]	169.56.71.47
[DHCP IP: (192.168.0.26)] to MAC address b0:e8:92:0c:77:73 	1	Tuesday, 07 Feb 2017 21:37:14	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.38)] to MAC address 02:0f:b5:b2:a6:b2 	6	Tuesday, 07 Feb 2017 21:27:25	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.22)] to MAC address 98:fe:94:11:c3:e3 	1	Tuesday, 07 Feb 2017 21:03:02	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.24)] to MAC address 5c:8d:4e:6f:64:6a 	1	Tuesday, 07 Feb 2017 20:57:41	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.36)] to MAC address 84:d6:d0:0a:3e:93 	1	Tuesday, 07 Feb 2017 20:36:48	0.0.0.0	0.0.0.0
[DoS attack] ICMP Flood from 169.56.71.55 	1	Tuesday, 07 Feb 2017 20:05:09	[My IP]	169.56.71.55
[DHCP IP: (192.168.0.22)] to MAC address 98:fe:94:11:c3:e3 	1	Tuesday, 07 Feb 2017 19:43:12	0.0.0.0	0.0.0.0
[DoS attack] ICMP Flood from 169.56.71.39 	1	Tuesday, 07 Feb 2017 19:09:11	[My IP]	169.56.71.39
[DHCP IP: (192.168.0.21)] to MAC address 44:8a:5b:5e:a7:6f 	1	Tuesday, 07 Feb 2017 17:39:04	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.39)] to MAC address 02:0f:b5:4a:56:a4 	1	Tuesday, 07 Feb 2017 17:28:01	0.0.0.0	0.0.0.0
[DHCP IP: (192.168.0.38)] to MAC address 02:0f:b5:b2:a6:b2 	1	Tuesday, 07 Feb 2017 17:23:52	0.0.0.0	0.0.0.0

 

Model: C6300|AC1750 Cable Modem Router Docsis 3.0
Message 1 of 4
DarrenM
Sr. NETGEAR Moderator

Re: C6300 Logs > DoS Attack

Hello griffin9

 

Are you able to post the signal levels of the modem?


DarrenM

Message 2 of 4
griffin9
Aspirant

Re: C6300 Logs > DoS Attack

I'm not certain if this is what you mean, but in hopes that it is:

CableInfo

Message 3 of 4
DarrenM
Sr. NETGEAR Moderator

Re: C6300 Logs > DoS Attack

Yes that is what I was asking for and the levels seem to be fine and I do not think its the DOS attacks. Does this disconnect and slow down happen at certain parts of the day?

 

DarrenM

Message 4 of 4
Top Contributors
Discussion stats
  • 3 replies
  • 3902 views
  • 0 kudos
  • 2 in conversation
Announcements

Orbi 770 Series