NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

bevant's avatar
bevant
Apprentice
Jan 18, 2021
Solved

XR500 question whether or not we can block a specific IP address doing DoS attack

Hi,

 

From time to time I get a DoS attack from a specific external IP address. My XR500 sends me a log every few minutes telling me that it's from a particular IP address. The attack can go on for hours. 

 

 

Is there some ways I can put these IP address in a blacklist so that it just ignores any attempts from the IP address?

 

It doesn't get through but it's just annoying. 

 

  • bevant you can only do what Liam suggested if you upgrade to the latest beta version. However, there is really no need to do this as it won't be causing any issues for you - in fact if you did block it you may find something you use on the internet stops working as those DoS entries tend to show connections you come in contact with. If the frequent entries annoy you then go to Settings > Monitoring > Logs and untick 'Known DoS attacks and Port Scans' then they will stop appearing.

8 Replies

  • Logs are verbose as they are primarily for developers. They are not meant for users to come up with an issue. DoS Attack entries are common on Netgear routers and do cause unnecessary panic. They appear just from browsing the internet etc, where abouts are you located? Looking up that IP shows a company in the Netherlands. The entries initially appear harmless and DoS protection is enabled by default anyway if there was something sinister happening you'd be protected.

    • bevant's avatar
      bevant
      Apprentice

      Hi Liam,

       

      I'm in Australia. I know I'm protected but it's just annoying it shows in the log ....just wondering if I can just ban that IP and get the router to ignore the IP altogether.;...

      but I guess I can just tell the log to ignore DoS entries?

      Thanks!

      • Netduma-Liam's avatar
        Netduma-Liam
        NetDuma Partner

        You could try blocking the IP in traffic controller? Not sure if this will stop the logs from registering it though.