- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
Re: Should I Try To Block These IP's?
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Should I Try To Block These IP's?
Hello,
With two people now working from home, I have noticed some unusual behaviors/slowdowns in browser response. I'm just learning the basics as far as diagnosing what might be improved and looked into the log on board my AX12. It shows a lot of "DoS Attack: ARP Attack" and "DoS Attack: TCP/UDP Echo" and "DoS Attack: SYN/ACK Scan". I can see the IP addresses associated with these attacks. I'm trying to figure out if these attacks might be the reasons for the change in performance/behavior on my browser and what to do to protect against/reduce/prevent them.
Is the first/basic step to block the source IP's?
If so, how do I do that?
Thank you,
Dude
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Should I Try To Block These IP's?
Netgear's firmware is great at creating false reports of DoS attacks. Many of them are no such thing.
Search - NETGEAR Communities – DoS attacks
Use Whois.net to see who is behind some of them and you may find that they are from places like Facebook, Google, even your ISP.
Here is a useful tool for that task:
IPNetInfo: Retrieve IP Address Information from WHOIS servers
@DudeRides wrote:
Is the first/basic step to block the source IP's?
Not if you want to use those sites.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Should I Try To Block These IP's?
Interesting. I parsed through most of the log from Thursday/Friday and indeed most of the IP addresses were from Charter, but there were a few from China and Indonesia.
Rather than blocking IP addresses, should I look for Ports to block?
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Should I Try To Block These IP's?
What tool is used to block IP's or Ports? I can't seem to find anything onboard the router to do so...
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Should I Try To Block These IP's?
Check the manual for your device. AX12 could be one of several things.
If you visit the support pages:
Support | NETGEAR
you can feed in the model number and find the documentation.
Look for the model number on the label on the device.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Should I Try To Block These IP's?
@DudeRides wrote:Interesting. I parsed through most of the log from Thursday/Friday and indeed most of the IP addresses were from Charter, but there were a few from China and Indonesia.
Rather than blocking IP addresses, should I look for Ports to block?
My internet provider is Spectrum (Charter) and had many DOS logged coming from IP within Spectrum. I was using an older firmware version for my router RAX80 1.0.1.56 after I upgraded to the latest 1.0.1.70 the entries went away. I believe the log entries with the older firmware were logged falsely. Because the router was logging the DOS attacks so often it was slowing down my connection. After I upgraded the firmware internet speed has returned to normal & no more DOS attack in the log.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Should I Try To Block These IP's?
@SAM_the_GAM wrote:
I believe the log entries with the older firmware were logged falsely.
Yup. That's what I said earlier, but it didn't seem to satisfy @DudeRides.
Thanks for providing concrete evidence with related hardware.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Should I Try To Block These IP's?
My firmware is already on the latest (1.0.1.114) so I can't at the moment eliminate the DoS entries from the log, however, I accept that they may be false. Nevertheless I'm left trying to dianose why the addition of my wife's work PC to the network has resulted in a change in the behavior of the network. A response on a different forum has suggested that I place her work PC on an isolated "VLAN". Thoughts?
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Should I Try To Block These IP's?
@DudeRides wrote:
...I can't at the moment eliminate the DoS entries from the log...
I don't know what "eliminate" means.
We still don't know what this AX12 might be – perhaps RAX120 or RAX200 – but the browser graphical user interface on most Netgear routers allows you to clean out the logs.
Get the manual and read the bit View and Manage Logs of Router Activity.
This will also explain how to turn off logging for various events, including these events.
Disabling that bit of the logging does not reduce your protection from nasties, but it does mean that your router will not bust a gut, and slow itself down, as it tries to write those events into the logs.
@DudeRides wrote:
A response on a different forum has suggested that I place her work PC on an isolated "VLAN". Thoughts?
I don't know what that means or where you read it, so my thoughts on that are worthless, beyond suggesting that trying a particular solution is not much help when you don't know what the problem is.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Should I Try To Block These IP's?
RAX120
It does look like I have the ability to disable logging of DoS attacks, but I'm hesitant to do that if it will help me determine what the issue is. As you said, I "don't know what the problem is." I'm trying to figure out the best way to go about figuring out what the problem is.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Should I Try To Block These IP's?
@DudeRides wrote:My firmware is already on the latest (1.0.1.114) so I can't at the moment eliminate the DoS entries from the log, however, I accept that they may be false. Nevertheless I'm left trying to dianose why the addition of my wife's work PC to the network has resulted in a change in the behavior of the network. A response on a different forum has suggested that I place her work PC on an isolated "VLAN". Thoughts?
There is a beta HOTFIX 1.0.1.118 http://www.downloads.netgear.com/files/GDC/RAX120/RAX120-V1.0.1.118_BETA.zip
• Introducing NETGEAR WiFi 7 Orbi 770 Series and Nighthawk RS300
• What is the difference between WiFi 6 and WiFi 7?
• Yes! WiFi 7 is backwards compatible with other Wifi devices? Learn more