× NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
× Introducing the new Orbi 770 Series Mesh System. To learn more click here.
Orbi WiFi 7 RBE973
Reply

Re: Should I Try To Block These IP's?

DudeRides
Aspirant

Should I Try To Block These IP's?

Hello,

 

With two people now working from home, I have noticed some unusual behaviors/slowdowns in browser response. I'm just learning the basics as far as diagnosing what might be improved and looked into the log on board my AX12. It shows a lot of "DoS Attack: ARP Attack" and "DoS Attack: TCP/UDP Echo" and "DoS Attack: SYN/ACK Scan". I can see the IP addresses associated with these attacks. I'm trying to figure out if these attacks might be the reasons for the change in performance/behavior on my browser and what to do to protect against/reduce/prevent them.

 

Is the first/basic step to block the source IP's?

 

If so, how do I do that?

Thank you,

 

Dude

Message 1 of 12

Re: Should I Try To Block These IP's?

Netgear's firmware is great at creating false reports of DoS attacks. Many of them are no such thing.

 

Search - NETGEAR Communities – DoS attacks

 

Use Whois.net to see who is behind some of them and you may find that they are from places like Facebook, Google, even your ISP.

 

Here is a useful tool for that task:

 

IPNetInfo: Retrieve IP Address Information from WHOIS servers

 


@DudeRides wrote:

 

Is the first/basic step to block the source IP's?

 

Not if you want to use those sites.

 

Message 2 of 12
DudeRides
Aspirant

Re: Should I Try To Block These IP's?

Interesting. I parsed through most of the log from Thursday/Friday and indeed most of the IP addresses were from Charter, but there were a few from China and Indonesia.

 

Rather than blocking IP addresses, should I look for Ports to block?

Message 3 of 12

Re: Should I Try To Block These IP's?


@DudeRides wrote:

 

Rather than blocking IP addresses, should I look for Ports to block?


Up to you.

 

 

 

 

Message 4 of 12
DudeRides
Aspirant

Re: Should I Try To Block These IP's?

What tool is used to block IP's or Ports? I can't seem to find anything onboard the router to do so...

Message 5 of 12

Re: Should I Try To Block These IP's?

Check the manual for your device. AX12 could be one of several things.

 

If you visit the support pages:

Support | NETGEAR

you can feed in the model number and find the documentation.

Look for the model number on the label on the device.

 

 

Message 6 of 12
SAM_the_GAM
Luminary

Re: Should I Try To Block These IP's?


@DudeRides wrote:

Interesting. I parsed through most of the log from Thursday/Friday and indeed most of the IP addresses were from Charter, but there were a few from China and Indonesia.

 

Rather than blocking IP addresses, should I look for Ports to block?


My internet provider is Spectrum (Charter) and had many DOS logged coming from IP within Spectrum. I was using an older firmware version for my router RAX80 1.0.1.56 after I upgraded to the latest 1.0.1.70 the entries went away. I believe the log entries with the older firmware were logged falsely. Because the router was logging the DOS attacks so often it was slowing down my connection. After I upgraded the firmware internet speed has returned to normal & no more DOS attack in the log. 

Model: RAX80|Nighthawk AX8 8-Stream WiFi Router
Message 7 of 12

Re: Should I Try To Block These IP's?


@SAM_the_GAM wrote:


I believe the log entries with the older firmware were logged falsely.


Yup. That's what I said earlier, but  it didn't seem to satisfy @DudeRides.

 

Thanks for providing concrete evidence with related hardware.

 

Message 8 of 12
DudeRides
Aspirant

Re: Should I Try To Block These IP's?

My firmware is already on the latest (1.0.1.114) so I can't at the moment eliminate the DoS entries from the log, however, I accept that they may be false. Nevertheless I'm left trying to dianose why the addition of my wife's work PC to the network has resulted in a change in the behavior of the network. A response on a different forum has suggested that I place her work PC on an isolated "VLAN". Thoughts?

Message 9 of 12

Re: Should I Try To Block These IP's?

 


@DudeRides wrote:

...I can't at the moment eliminate the DoS entries from the log...

 


I don't know what "eliminate" means.

 

We still don't know what this AX12 might be –  perhaps RAX120 or RAX200 – but the browser graphical user interface on most Netgear routers allows you to clean out the logs.

 

Get the manual and read the bit View and Manage Logs of Router Activity.

 

This will also explain how to turn off logging for various events, including these events.

 

Disabling that bit of the logging does not reduce your protection from nasties, but it does mean that your router will not bust a gut, and slow itself down, as it tries to write those events into the logs.

 


@DudeRides wrote:

A response on a different forum has suggested that I place her work PC on an isolated "VLAN". Thoughts?


I don't know what that means or where you read it, so my thoughts on that are worthless, beyond suggesting that trying a particular solution is not much help when you don't know what the problem is.

Message 10 of 12
DudeRides
Aspirant

Re: Should I Try To Block These IP's?

RAX120

 

It does look like I have the ability to disable logging of DoS attacks, but I'm hesitant to do that if it will help me determine what the issue is. As you said, I "don't know what the problem is." I'm trying to figure out the best way to go about figuring out what the problem is.

Message 11 of 12
SAM_the_GAM
Luminary

Re: Should I Try To Block These IP's?


@DudeRides wrote:

My firmware is already on the latest (1.0.1.114) so I can't at the moment eliminate the DoS entries from the log, however, I accept that they may be false. Nevertheless I'm left trying to dianose why the addition of my wife's work PC to the network has resulted in a change in the behavior of the network. A response on a different forum has suggested that I place her work PC on an isolated "VLAN". Thoughts?


There is a beta HOTFIX 1.0.1.118  http://www.downloads.netgear.com/files/GDC/RAX120/RAX120-V1.0.1.118_BETA.zip

 

Message 12 of 12
Top Contributors
Discussion stats
  • 11 replies
  • 2573 views
  • 1 kudo
  • 3 in conversation
Announcements

Orbi 770 Series