Orbi WiFi 7 RBE973
Reply

Re: Question about Attack Warning

MMorgan707
Aspirant

Question about Attack Warning

I received an "Attack" message from NETGEAR "Armor detected that a suspicious remote location 188.240.13.2 attempted a connection to Pixel-7-Pro and blocked that connection.  We will keep an eye on this device for you.  You're protected and don't need to do anything else"

 

Is this common or something I need to do more about?

Message 1 of 10
MMorgan707
Aspirant

"Attack" Message

Looking for an opinion on an "Attack" message I received:   "NETGEAR Armor detected that a suspicious remote location 188.240.13.2 attempted a connection to Pixel-7-Pro and blocked that connection.  We will keep an eye on the this device for you.  You're protected and don't need to do anything."   I was concerned because it is an attack on a specific device and the message alerted 4 to 5 times and on different days. 

 

Has anyone received this message or know if this is something to worry further about?

 

Thanks,

Message 2 of 10
FURRYe38
Guru

Re: Question about Attack Warning

Just Armor letting you know that it's doing it's job. 

Can do a Whois look up on that IP address to see where that is coming from if you like. 

 

Otherwise, normal to get notices from Armor about items it blocks. 

Message 3 of 10
MMorgan707
Aspirant

Re: Question about Attack Warning

Do you think it is odd that it was tied to a specific device such as my phone?

Message 4 of 10
FURRYe38
Guru

Re: Question about Attack Warning

No. Could be picked up on any or maybe some targeted attempt. 

Message 5 of 10
Chrisb12
Aspirant

Re: Question about Attack Warning

I'm getting the same message from the same IP address.
Message 6 of 10
FURRYe38
Guru

Re: "Attack" Message

IP shows from this company:

inetnum: 188.240.13.0 - 188.240.13.255
netname: NL-DATAWEBGLOBALGROUP-20090623
country: NL

 

https://datawebgroup.com 

Message 7 of 10
BrianRubin
Initiate

Re: Question about Attack Warning

Hey, I'm having the same issue. 

“NETGEAR Armor detected that a suspicious location 151.101.1.91 attempted a connection to [device here] and blocked that connection.”

It's always the same IP. The IP is owned by a company called Fastly, and they can't figure out what's going on. 

Is there anything I can do or should be doing about this?

 

Thank you. 

Message 8 of 10
Topology
Virtuoso

Re: Question about Attack Warning

One resource that may be helpful when investigating suspicious IP addresses is the Abuse IP Database service.

Message 9 of 10
BrianRubin
Initiate

Re: Question about Attack Warning

Ah, so likely something not to worry about then. Okay, great. Thank you!

Message 10 of 10
Top Contributors
Discussion stats
  • 9 replies
  • 3533 views
  • 1 kudo
  • 5 in conversation
Announcements

Orbi 770 Series