Orbi WiFi 7 RBE973
Reply

Router mvpn purge and suspicious insight xcloud communication with orbi pro sxr80

Orbipro1
Aspirant

Router mvpn purge and suspicious insight xcloud communication with orbi pro sxr80

Not able to identify source of these router insight interactions with my orbi pro:

 

Have not enrolled in insight. May be unauthorized access and actions?  What do they Mean?

 

log;

[Insight] Purge mvpn service successfully., Sunday, November 20, 2022 01:55:25

[Insight] Disable concentrator mvpn., Sunday, November 20, 2022 01:55:25

[Insight] Disable content filtering successfully., Sunday, November 20, 2022 01:55:25

[Insight] Set auto_upgrade to 1., Sunday, November 20, 2022 01:55:25

[Insight] Set upgrade http url to ., Sunday, November 20, 2022 01:55:25

[Insight] Device is not claimed on Insight cloud (1003)., Sunday, November 20, 2022 01:55:25

[Insight] Boot API request: data = {"serialNo":"6KW10B5XA4EAF","macAddress":"9c:c9:eb:dd:1d:f3","model":"SXR80","xDeviceId":"GEDNAGV7-3220-336-184411967","deviceType":"ORBI","fwVersion":"4.2.3.102","sendPendingC, Sunday, November 20, 2022 01:55:24

[Insight] Register the device and send request to get device token., Sunday, November 20, 2022 01:55:24

[Insight] Need to request device token. is_registered = 0, is_claimed = 0, is_token_empty = 1, Sunday, November 20, 2022 01:55:16

[Insight] insight-brokerd was initialized. Start the main loop., Sunday, November 20, 2022 01:55:16

[Insight] Syslog worker was started., Sunday, November 20, 2022 01:55:16

[Insight] Notification worker was started., Sunday, November 20, 2022 01:55:16

[Insight] Monitoring worker was started., Sunday, November 20, 2022 01:55:16

[Insight] Health worker was started., Sunday, November 20, 2022 01:55:16

[Insight] cli worker was started., Sunday, November 20, 2022 01:55:16

[Insight] Config event worker was started., Sunday, November 20, 2022 01:55:16

[Insight] Got the xagent id., Sunday, November 20, 2022 01:55:16

[Insight] System info: device_type = ORBI, serial_number = 6KW10B5XA4EAF, model_name = SXR80, firmware_version = 4.2.3.102, insight_cert_path = /opt/netgear/usr/share/combined_intermediates_and_root.crt, config_, Sunday, November 20, 2022 01:55:16

[DoS Attack: ACK Scan] from source: 3.94.89.212, port 443, Sunday, November 20, 2022 01:55:15

[Insight] configd init completed., Sunday, November 20, 2022 01:55:15

[Insight] Failed to get system info from configd. Retry after 2 seconds., Sunday, November 20, 2022 01:55:14

[Insight] insight-configd was started., Sunday, November 20, 2022 01:55:12

[Insight] Failed to get system info from configd. Retry after 2 seconds., Sunday, November 20, 2022 01:55:12

[Insight] Connect to prod server., Sunday, November 20, 2022 01:55:12

[Insight] The agent config files were checked and validated., Sunday, November 20, 2022 01:55:11

[DoS Attack: ACK Scan] from source: 3.94.89.212, port 443, Sunday, November 20, 2022 01:55:10

[Insight] Set dns /opt/netgear/usr/share/cloud_dns_urls/extend_pass_domains_prod successfully., Sunday, November 20, 2022 01:55:09

[Insight] cli_server is prod, cd_ver is 53, target server is prod, Sunday, November 20, 2022 01:55:09

[DoS Attack: ACK Scan] from source: 3.94.89.212, port 443, Sunday, November 20, 2022 01:55:05

Message 1 of 4

Accepted Solutions
schumaku
Guru

Re: Router mvpn purge and suspicious insight xcloud communication with orbi pro sxr80


@Orbipro1 wrote:

Do you think I would be safer to register and manage device with insight cloud application interface, than to leave device unclaimed and open to enrollment by someone, something else?


it's  commodity option allowing the Insight admin to bring the device into the Insight cloud in an easier way. This process does still require additional actions, not aware a third party can trigger something you might not want.

 


@Orbipro1 wrote:

Have been experience disruptions, suspicious delays on mobile device that coincide with those communications. Maybe a iOS deficiency, apple relay, or dns service.


The sequence of [insight] messages does make me believe the system was either restarted, rebooted, or it has re-established the connection to the internet recently. Whatever impact or effect this had on your mobile device...

View solution in original post

Message 4 of 4

All Replies
schumaku
Guru

Re: Router mvpn purge and suspicious insight xcloud communication with orbi pro sxr80

As answered before. Nothing suspicious.

Message 2 of 4
Orbipro1
Aspirant

Re: Router mvpn purge and suspicious insight xcloud communication with orbi pro sxr80

Automated cloud communication, maintenance, administration without a clear explanation from Netgear. 

 

Thank you for your explanation.

 

Do you think I would be safer to register and manage device with insight cloud application interface, than to leave device unclaimed and open to enrollment by someone, something else?

 

i did not sign up for any cloud services or cloud filtering or firewall. 

 

I have not seen these recent actions and executions in my logs previously.

 

Have been experience disruptions, suspicious delays on mobile device that coincide with those communications. Maybe a iOS deficiency, apple relay, or dns service.

 

 

Message 3 of 4
schumaku
Guru

Re: Router mvpn purge and suspicious insight xcloud communication with orbi pro sxr80


@Orbipro1 wrote:

Do you think I would be safer to register and manage device with insight cloud application interface, than to leave device unclaimed and open to enrollment by someone, something else?


it's  commodity option allowing the Insight admin to bring the device into the Insight cloud in an easier way. This process does still require additional actions, not aware a third party can trigger something you might not want.

 


@Orbipro1 wrote:

Have been experience disruptions, suspicious delays on mobile device that coincide with those communications. Maybe a iOS deficiency, apple relay, or dns service.


The sequence of [insight] messages does make me believe the system was either restarted, rebooted, or it has re-established the connection to the internet recently. Whatever impact or effect this had on your mobile device...

Message 4 of 4
Top Contributors
Discussion stats
  • 3 replies
  • 1343 views
  • 1 kudo
  • 2 in conversation
Announcements