Who Me Too'd this solution

Babylon5
NETGEAR Employee Retired

Re: Disable Port Scan and DoS Protection

It can be useful, but that depends on the situation and how you interpret the data. As Fordem points out it really only gives an indication of what is happening, and if you really were the target of a DoS attack it might help in diagnosing what is going on. However DoS attacks on individuals are extremely rare, it takes effort to set up and would be wasteful to use ‘just for a laugh’. What we often see on these forums is people who are concerned at the log listings they see, and are after some explanation / reassurance that all is OK.

So personally I would say not completely useless, and unfortunately often misinterpreted and a source of paranoia.

Just to add a little perspective to this, before I used a NAT router I had a PC connected directly to a cable modem running Zone Alarm. I used to see hundreds or thousands of hits per day, so many that I also had a utility for analysing the logs. After a few months of regularly inspecting the logs I got completely bored with the whole process. I can’t really describe how pointless it was but I would say that it’s similar to walking into a noisy bar and trying to listen to every conversation to see if anyone is talking about me.

After installing a NAT router the Zone Alarm reports dropped to zero, I no longer use it. I spent a while looking at the router logs (a small business grade router) and eventually gave up on that, I don’t even bother with the log e-mails anymore. Occasionally I have an issue with an IP camera on my LAN attempting to ‘spam’ an IP address, my router protects in both directions and blocks that from happening, this is about the best use I have for that log, to see when the camera is having one of its 'episodes'.

View solution in original post

Who Me Too'd this solution