× NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Announcements

Polls
What is your Experience with NETGEAR Insight cloud management?
Top Contributors

More information in the log to be able to tune the DDoS (due to "False Positive")

Problem statement: GS324T deactivates the port due to suspected DDoS, but most likely it is a false positive - tuning is not really possible due to the missing information (in the log) about the reason(s).

 

The Switch log shows only one line:

 

<11> Apr 11 04:55:29 Main Home Switch-1 DOS[dtlTask]: dos_api.c(1928) 2115 %% ERR Interface g12 has been shutdown by DOS attack notification.

Based on the reply on my post in the forum here, it looks like there is no possibility to have more information in the log, and identify the  real reasons, what exactly has triggered the port deactivation. 
Hence, there is no possibility to "tune" the DDOS settings and avoid the "False Positive".
In other words: only "blind" tuning possible.

 

Ask:
To have the possibility to get more details about DDoS to the log e.g. by having different log level for DDoS, up to the additional information what exactly / what "active" parameter in DDoS settings has triggered the port deactivation.

 

Thanks, Andrey