- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
CONSTANT DOS ATTACKS & DISCONNECTION
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
CONSTANT DOS ATTACKS & DISCONNECTION
For the last two weeks, my internet has been acting up and keeps just randomly disconnecting. Only for a couple of seconds but it happens back to back all day long. Can someone help me understand whats happening. I have never had any issues before and the router was bought back in November of last year. This is what my log looks like...
admin login] from source 0.0.0.0 | 1 | Thu May 06 14:31:10 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[DHCP IP: 192.168.0.13] to MAC address f0:18:98:a4:f6:ab | 1 | Thu May 06 14:31:08 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet connected] IP address: 73.28.71.3 | 1 | Thu May 06 14:00:01 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Time synchronized with ToD server] | 1 | Thu May 06 13:59:47 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet disconnected] | 1 | Thu May 06 13:57:52 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet connected] IP address: 73.28.71.3 | 1 | Thu May 06 13:37:50 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Time synchronized with ToD server] | 1 | Thu May 06 13:37:36 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet disconnected] | 1 | Thu May 06 13:37:05 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet connected] IP address: 73.28.71.3 | 1 | Thu May 06 13:30:01 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Time synchronized with ToD server] | 1 | Thu May 06 13:29:48 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet disconnected] | 1 | Thu May 06 13:29:18 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Thu May 06 13:20:18 2021 | 73.28.71.3:64045 | 8.8.8.8:53 |
[DHCP IP: 192.168.0.11] to MAC address 62:18:d3:62:53:1f | 1 | Thu May 06 13:20:15 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet connected] IP address: 73.28.71.3 | 1 | Thu May 06 13:12:55 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Time synchronized with ToD server] | 1 | Thu May 06 13:12:40 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet disconnected] | 1 | Thu May 06 13:12:11 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet connected] IP address: 73.28.71.3 | 1 | Thu May 06 12:37:48 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Time synchronized with ToD server] | 1 | Thu May 06 12:37:34 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet disconnected] | 1 | Thu May 06 12:37:01 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet connected] IP address: 73.28.71.3 | 1 | Thu May 06 11:42:46 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Time synchronized with ToD server] | 1 | Thu May 06 11:42:33 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet disconnected] | 1 | Thu May 06 11:42:05 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Thu May 06 08:49:22 2021 | 73.28.71.3:53402 | 8.8.8.8:53 |
[DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Thu May 06 08:42:54 2021 | 73.28.71.3:63872 | 8.8.8.8:53 |
[DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Thu May 06 08:35:26 2021 | 73.28.71.3:55626 | 8.8.8.8:53 |
[DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Thu May 06 08:19:36 2021 | 73.28.71.3:64277 | 8.8.8.8:53 |
[Internet connected] IP address: 73.28.71.3 | 1 | Thu May 06 08:14:17 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Time synchronized with ToD server] | 1 | Thu May 06 08:14:03 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet disconnected] | 1 | Thu May 06 08:13:27 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Thu May 06 07:24:17 2021 | 73.28.71.3:56225 | 8.8.8.8:53 |
[DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Thu May 06 06:31:20 2021 | 73.28.71.3:52103 | 8.8.8.8:53 |
[DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Thu May 06 06:07:38 2021 | 73.28.71.3:65205 | 8.8.8.8:53 |
[DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Thu May 06 06:03:44 2021 | 73.28.71.3:49358 | 8.8.8.8:53 |
[DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Thu May 06 05:48:26 2021 | 73.28.71.3:51577 | 8.8.8.8:53 |
[DHCP IP: 192.168.0.11] to MAC address 62:18:d3:62:53:1f | 1 | Thu May 06 05:48:25 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[DHCP IP: 192.168.0.11] to MAC address 62:18:d3:62:53:1f | 1 | Thu May 06 05:48:24 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet connected] IP address: 73.28.71.3 | 1 | Thu May 06 02:02:13 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Time synchronized with ToD server] | 1 | Thu May 06 02:01:58 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet disconnected] | 1 | Thu May 06 02:01:22 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[UPnP set event: DeletePortMapping] from source 192.168.0.17 | 1 | Thu May 06 01:20:59 2021 | 0.0.0.0:0 | 192.168.0.17:0 |
[UPnP set event: GetExternalIPAddress] from source 192.168.0.17 | 1 | Thu May 06 01:20:59 2021 | 0.0.0.0:0 | 192.168.0.17:0 |
[UPnP set event: AddPortMapping] from source 192.168.0.17 | 1 | Thu May 06 01:20:25 2021 | 0.0.0.0:0 | 192.168.0.17:0 |
[UPnP set event: GetExternalIPAddress] from source 192.168.0.17 | 1 | Thu May 06 01:20:25 2021 | 0.0.0.0:0 | 192.168.0.17:0 |
[DHCP IP: 192.168.0.17] to MAC address 4c:3b:df:73:81:1d | 1 | Thu May 06 01:20:25 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet connected] IP address: 73.28.71.3 | 1 | Thu May 06 00:29:59 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Time synchronized with ToD server] | 1 | Thu May 06 00:29:44 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet disconnected] | 1 | Thu May 06 00:29:12 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet connected] IP address: 73.28.71.3 | 1 | Wed May 05 23:36:08 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Time synchronized with ToD server] | 1 | Wed May 05 23:35:54 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet disconnected] | 1 | Wed May 05 23:32:53 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet connected] IP address: 73.28.71.3 | 1 | Wed May 05 22:06:22 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Time synchronized with ToD server] | 1 | Wed May 05 22:06:09 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet disconnected] | 1 | Wed May 05 22:05:42 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[DHCP IP: 192.168.0.17] to MAC address 4c:3b:df:73:81:1d | 1 | Wed May 05 22:03:01 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[DHCP IP: 192.168.0.17] to MAC address 4c:3b:df:73:81:1d | 1 | Wed May 05 22:02:30 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Wed May 05 21:34:03 2021 | 73.28.71.3:56201 | 8.8.8.8:53 |
[DoS attack: SYN Flood] from 52.143.79.188, port 443 | 1 | Wed May 05 21:17:46 2021 | 192.168.0.17:49940 | 52.143.79.188:443 |
[DoS attack: SYN Flood] from 52.251.11.100, port 443 | 1 | Wed May 05 21:17:36 2021 | 192.168.0.17:49883 | 52.251.11.100:443 |
[DoS attack: SYN Flood] from 40.70.154.148, port 443 | 1 | Wed May 05 21:17:32 2021 | 192.168.0.17:49844 | 40.70.154.148:443 |
[DoS attack: SYN Flood] from 104.94.108.9, port 443 | 1 | Wed May 05 21:17:13 2021 | 192.168.0.17:49802 | 104.94.108.9:443 |
[UPnP set event: AddPortMapping] from source 192.168.0.17 | 1 | Wed May 05 21:17:06 2021 | 0.0.0.0:0 | 192.168.0.17:0 |
[UPnP set event: GetExternalIPAddress] from source 192.168.0.17 | 1 | Wed May 05 21:17:06 2021 | 0.0.0.0:0 | 192.168.0.17:0 |
[DHCP IP: 192.168.0.17] to MAC address 4c:3b:df:73:81:1d | 1 | Wed May 05 21:17:06 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Wed May 05 21:13:29 2021 | 73.28.71.3:55320 | 8.8.8.8:53 |
[DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Wed May 05 21:06:01 2021 | 73.28.71.3:49535 | 8.8.8.8:53 |
[DHCP IP: 192.168.0.11] to MAC address 62:18:d3:62:53:1f | 1 | Wed May 05 21:05:59 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet connected] IP address: 73.28.71.3 | 1 | Wed May 05 21:00:17 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Time synchronized with ToD server] | 1 | Wed May 05 21:00:03 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet disconnected] | 1 | Wed May 05 20:59:23 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet connected] IP address: 73.28.71.3 | 1 | Wed May 05 18:48:04 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Time synchronized with ToD server] | 1 | Wed May 05 18:47:50 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[Internet disconnected] | 1 | Wed May 05 18:47:21 2021 | 0.0.0.0:0 | 0.0.0.0:0 |
[DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Wed May 05 16:59:34 2021 | 73.28.71.3:55071 | 8.8.8.8:53 |
[DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Wed May 05 16:54:07 2021 | 73.28.71.3:58335 | 8.8.8.8:53 |
[DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Wed May 05 16:41:31 2021 | 73.28.71.3:58711 | 8.8.8.8:53 |
[DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Wed May 05 16:36:51 2021 | 73.28.71.3:49410 | 8.8.8.8:53 |
[DoS attack: TCP- or UDP-based Port Scan] from 8.8.4.4, port 53 | 1 | Wed May 05 16:35:20 2021 | 73.28.71.3:62235 | 8.8.4.4:53 |
[DoS attack: SYN Flood] from 17.248.137.108, port 443 | 1 | Wed May 05 16:35:05 2021 | 192.168.0.11:64459 | 17.248.137.108:443 |
[DoS attack: TCP- or UDP-based Port Scan] from 1.1.1.1, port 53 | 1 | Wed May 05 16:35:04 2021 | 73.28.71.3:63401 | 1.1.1.1:53 |
[DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Wed May 05 16:34:53 2021 | 73.28.71.3:58432 | 8.8.8.8:53 |
[DoS attack: TCP- or UDP-based Port Scan] from 8.8.8.8, port 53 | 1 | Wed May 05 16:31:17 2021 | 73.28.71.3:57693 | 8.8.8.8:53 |
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: CONSTANT DOS ATTACKS & DISCONNECTION
Have you checked the logs of the ISP modem to see if you have any T3 or T4 timeouts?
DarrenM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: CONSTANT DOS ATTACKS & DISCONNECTION
were you able to fix this issue?, what was causing it, and what was the solution?
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: CONSTANT DOS ATTACKS & DISCONNECTION
NETGEAR is famously known for many false positives DoS attacks. Their "protection" is virtually useless. I suggest turnning off DoS protection completely off and see if you get a stable device. Myself, I've been running without DoS protection since I bought my router (3.5 years ago) and never had an issue.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: CONSTANT DOS ATTACKS & DISCONNECTION
What NG product do you have?
What is the Mfr and model# of the Internet Service Providers modem/ONT the NG router is connected too?
@carapungo wrote:
were you able to fix this issue?, what was causing it, and what was the solution?
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: CONSTANT DOS ATTACKS & DISCONNECTION
Thanks. That's what I did this morning, and now my event log is empty, which I assume is a good thing. I have not seen any connection drops so far.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: CONSTANT DOS ATTACKS & DISCONNECTION
What NG product do you have?
What is the Mfr and model# of the Internet Service Providers modem/ONT the NG router is connected too?
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: CONSTANT DOS ATTACKS & DISCONNECTION
I have a Nighthawk C7000v2, using Comcast
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: CONSTANT DOS ATTACKS & DISCONNECTION
Netgear has set up a community forum specifically for the Cable Modem products. Most of the people who watch that forum are more likely to have experience with Cable modems and know how to work it better than those of us who follow this router forum. Might be more likely to find someone who has a solution if the question is posted there:
https://community.netgear.com/t5/Cable-Modems-Routers/bd-p/home-cable-modems-routers
Please make a new post there.
Please use this link to the main forum product list to review and choose where to make your posts.
https://community.netgear.com/t5/NETGEAR-Forum/ct-p/en-netgear
Thank you.
@carapungo wrote:
I have a Nighthawk C7000v2, using Comcast
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: CONSTANT DOS ATTACKS & DISCONNECTION
So, I actually had to contact my ISP (xfinity) and end up getting an entirely new IP address for my router. Nothing else was working. I havent had an issue since then.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: CONSTANT DOS ATTACKS & DISCONNECTION
Sounds like this was coming in from the ISP side then.
Please mark your thread as solved so others will know.
Be sure to save off a back up configuration to file for safe keeping. Saves time if a reset is needed.
https://kb.netgear.com/24231/How-do-I-back-up-the-router-configuration-settings-on-my-Nighthawk-rout...
Enjoy.
@yagirlchels wrote:
So, I actually had to contact my ISP (xfinity) and end up getting an entirely new IP address for my router. Nothing else was working. I havent had an issue since then.
• Introducing NETGEAR WiFi 7 Orbi 770 Series and Nighthawk RS300
• What is the difference between WiFi 6 and WiFi 7?
• Yes! WiFi 7 is backwards compatible with other Wifi devices? Learn more