Orbi WiFi 7 RBE973
Reply

Router locking up? Wifi failing? No internet? Turn off DNS Proxy!

rothe
Aspirant

Router locking up? Wifi failing? No internet? Turn off DNS Proxy!

My low-end, business-grade router has been having increasingly common failures over the past year, but the problem really got bad over the last month. It finally prompted me to look for solutions, and I found these two articles:

http://www.darkreading.com/cloud/sharp-rise-in-dns-based-ddos-last-year-signals-larger-more-frequent...

https://threatpost.com/dns-based-amplification-attacks-key-on-home-routers/105220

Neither article - or any other that I found among the first few searches that I did - said anything about a solution as simple as turning off the DNS proxy in the router, but that seems to have worked in my case. The ramifications of this are that attached systems will have to go out to your ISP's DNS servers for every name request - in other words, very slightly slowing web page loads - but the ISP's servers will likely be robust enough to not have problems related to the above mentioned vulnerability. It seems that some of our routers do.

The longer term solution will likely involve a firmware update that fixes the DNS proxy so that it can no longer be corrupted by unrequested, WAN-side DNS updates. But knowing our favorite vendor, that might take a while.

In the meantime, try this easy workaround. Post back with your results, and please mention the router model that you have.

Hope that helps!

Jim Rothe, CISSP
running a Netgear FVS318N
Message 1 of 10
rothe
Aspirant

Re: Router locking up? Wifi failing? No internet? Turn off DNS Proxy!

Should also mention that I'm running the 4.3.0-19 firmware on my FVS318N. That seems to be the last version that has proven stable for me. I've tried 4.3.1-22, 4.3.1-31 and 4.3.2-7, and all have exhibited similar periodic lockups.
Message 2 of 10
SamirD
Prodigy

Re: Router locking up? Wifi failing? No internet? Turn off DNS Proxy!

I have dns proxy off on my vlan which also has a site-to-site tunnel. But I noticed it was on for the wireless vlan. I've turned it off. Let's see if that fixes any issues. I'm on an older firmware than yours.
Message 3 of 10
rbalcorn
Novice

Re: Router locking up? Wifi failing? No internet? Turn off DNS Proxy!

I just bought one of these routers/firewalls a few days ago and I also noticed the DNS proxy was making it lock up. I upgraded to the latest firmware and that hasn't helped.

I am really disappoint in this box. :mad:

I will take your suggestion and I will try back rev'ing the firmware and see if that helps.

Thanks
Message 4 of 10
rothe
Aspirant

Re: Router locking up? Wifi failing? No internet? Turn off DNS Proxy!

FWIW, it seems that the open DNS Proxy issue affects a number of Netgear router models. Also, it seems that more than a few of the Prosafe line share the same firmware, or at least some very similar code such that they share numbering schemes.

As such, please remember to post your router model number and firmware version. This might help us to identify a reliable combination of firmware and settings.
Message 5 of 10
rbalcorn
Novice

Re: Router locking up? Wifi failing? No internet? Turn off DNS Proxy!

Yes, I agree. After searching on this, I have come to the same conclusion; it is not just the FVS318N that is affected. I have a FVS318N, currently running the latest firmware, 4.3.2-7, connected to a Motorola AB6121 cable modem. I believe the FVS318N came with 4.3.1-22, which was giving me problems as well. With the current setup, and with wireless disabled, DNS proxy on, it is working okay. However, shortly after enabling the wireless, it will lock up. I am going to try the 4.3.0-19 to see if it works any better than what I have now.
Message 6 of 10
rbalcorn
Novice

Re: Router locking up? Wifi failing? No internet? Turn off DNS Proxy!

Okay I back rev'd this piece of garb to 4.3.0-19 and it still doesn't work for more than 6 hours. Better, yes, but, not acceptable.

What I would like to know is if anyone out there has a FVS318N that actually works!! and they use all the features?

I am really disappoint with this product and I would not recommend it to anyone.

BTW, I have plenty of NetGear swtichs, and I have never had a problem with them; they work GREAT and last a long time!
Message 7 of 10
SamirD
Prodigy

Re: Router locking up? Wifi failing? No internet? Turn off DNS Proxy!

rbalcorn wrote:
Okay I back rev'd this piece of garb to 4.3.0-19 and it still doesn't work for more than 6 hours. Better, yes, but, not acceptable.

What I would like to know is if anyone out there has a FVS318N that actually works!! and they use all the features?

I am really disappoint with this product and I would not recommend it to anyone.

BTW, I have plenty of NetGear swtichs, and I have never had a problem with them; they work GREAT and last a long time!
4.0.1-67 and 4.3.0-19 both with vpn tunnels, vlans, wireless and neither one has been rebooted in months. Wireless on the 4.0.1 was quirky, but I think turning off the dns proxy fixed that. 🙂
Message 8 of 10
KWheelerAZ
Aspirant

Re: Router locking up? Wifi failing? No internet? Turn off DNS Proxy!

Speaking generically, I almost NEVER enable DNS Proxy on ANY of my firewalls. In fact, I frequently use Google's Public DNS or OpenDNS instead of the ISP's DNS servers.

I have never had these issues with any FVS318N under my control ... and I have about a dozen.
Message 9 of 10
SamirD
Prodigy

Re: Router locking up? Wifi failing? No internet? Turn off DNS Proxy!

KWheelerAZ wrote:
Speaking generically, I almost NEVER enable DNS Proxy on ANY of my firewalls. In fact, I frequently use Google's Public DNS or OpenDNS instead of the ISP's DNS servers.

I have never had these issues with any FVS318N under my control ... and I have about a dozen.
Great to hear! What firmwares? I also changed to google dns on one of mine because dns just wasn't working.
Message 10 of 10
Top Contributors
Discussion stats
  • 9 replies
  • 9820 views
  • 0 kudos
  • 4 in conversation
Announcements