Orbi WiFi 7 RBE973
Reply

Internet dropping, logs say dos attack icmp flood from different ips (C6300v2)

ButterSquatch
Aspirant

Internet dropping, logs say dos attack icmp flood from different ips (C6300v2)

Hello, 

I have been having this issue for about two weeks now. My wireless devices will randomly drop connection and when I'm on my desktop (wired) I get lag and or bad packet loss also randomly. especially while playing games and sometimes while browsing the internet. I have tried to do accouple of things that hasn't worked including changing my DNS, changing my coax to the modem and ethernet to my pc, and resetting my modem quite a few times. I have contacted my ISP (cox) and they believe its an issue with wiring and sending a tech out to look into it. I have noticed that it will drop sometimes when there isn't a ICMP flood. I'm just getting frustrated with this and would like some help figuring it out and solving it. I will attach screen shots of the logs and event logs to see if that will help.

 

My MODEL is the C6300v2, FIRMWARE is V1.03.04 (there is no update firmware in the admin setting of modem). 

 

Could a damaged cable or connection cause this? 

 

Is it my ISP screwing me over in a bit to make me upgrade/ Them putting too many people on there service in one area? (live in an apartment)

 

Some of the ICMP floods are random IP addresses and it seems to me to be hitting my modems IP not any devices on my network (if that's a thing idk about network stuff) that IP on the logs as the target is the same one under internet port in the advanced home. some of the more recent IP addresses are coming from AWS but some of the old ones where from random places like Denver and Albania. There is a constant ICMP flood from  fe80:0000:0000:0000:6e13:d5ff:fe21:d019 about every 10 min. form what I could find this is just the ISP talking to my router?? 

 

Any help would be appreciated greatly thank you.

 

logs .pngevent logs 7-23.png

 

 

Message 1 of 15
FURRYe38
Guru

Re: Internet dropping, logs say dos attack icmp flood from different ips (C6300v2)

Please post a copy and paste of the modems connection status page.

Message 2 of 15
ButterSquatch
Aspirant

Re: Internet dropping, logs say dos attack icmp flood from different ips (C6300v2)

not sure which one is the connection status screen but all the things say they are green and connected. Ill attach what I think you are asking about. Just let me know if its not the right thing. 

Thank you for the reply! 

Also have notice there is more ICMP flood attacks in the logs more from amazon and again some from other places around the world. could my Alexa's be causing this?

 

 

connection.png

Message 3 of 15
ButterSquatch
Aspirant

Re: Internet dropping, logs say dos attack icmp flood from different ips (C6300v2)

Message 4 of 15
ButterSquatch
Aspirant

Re: Internet dropping, logs say dos attack icmp flood from different ips (C6300v2)

Checked the cable connection again tonight and this is what it is showing. I'm still getting drops in service and those ICMP flood dos attacks are still happening from random IP addresses. 

Ill attach screen caps of both. 

connections 7-24.pnglogs 7-24.png

Message 5 of 15
FURRYe38
Guru

Re: Internet dropping, logs say dos attack icmp flood from different ips (C6300v2)

You have come correct and un-correctables that should be Zeros. Check and make sure all fittings are snug, no kinks in the cable line up to the modem. Be sure your using good quality RG6 coax cabling. Remove any coax line splitters. 

 

The power is TOO high. ISP needs to turn the power down:

https://kb.netgear.com/24311/Power-level-guidelines-for-a-NETGEAR-cable-modem-router?article=24311

 

Lots of Criticals that the ISP needs to look at as well. Have the ISP check the signal and line quality UP to the modem. Be sure the ISP provisions the modem correctly.

Message 6 of 15
ButterSquatch
Aspirant

Re: Internet dropping, logs say dos attack icmp flood from different ips (C6300v2)

@FURRYe38  

Tech came by today and said the line was good, said the power was too high and lowered the power. After they left I rebooted the router and there wasn't any correctable or uncorrectable and the internet seemed to be fine. Checked the admin page later and there is a bunch of correctable and uncorrectable and there is still more of those ICMP FLOOD DOS attacks from random IP addresses. But, I haven't had any issues with loosing connect so far. About to see if that still holds true with playing some games. 

Should I be worried about the multiple [DOS attack] ICMP Flood attacks ? 

Should I be worried about the PORT Scan PROTO TCP dos attack?? (source IP is 60.161.81.116 somewhere in china)

If I still have issues what should I do, the tech said the lines looked fine and lowered the power with a thing he put on the coax?

Also haven't had any more criticals since the tech came. 

Ill attach screen shots again. 

Some clarification on if those two types of dos attacks are a security threat and if so how to protect myself would be greatly appreciated, to but me at ease or into action. 

Screenshot 2022-07-25 212556.pngScreenshot 2022-07-25 212754.png

 

Message 7 of 15
ButterSquatch
Aspirant

Re: Internet dropping, logs say dos attack icmp flood from different ips (C6300v2)

Played some games and had no issues so the internet dropping and packet loss issue is fix yay!

Only thing now is should I be worried about the Dos attacks and the Port scan proto? 

there was another one while I was playing squad an online game. 

the line says [Dos attack] Port Scan PROTO:TCP SPT: some numbers and then DPT: some numbers from another IP from china from TenCent cloud computing. 

So basically should I be worried about those ? 

Message 8 of 15
FURRYe38
Guru

Re: Internet dropping, logs say dos attack icmp flood from different ips (C6300v2)

You still have too much Correct and Uncorrecables. 

 

Most of the time these attacks are just that, attacks that were blocked and just reported in the logs by the system. 

 

Message 9 of 15
ButterSquatch
Aspirant

Re: Internet dropping, logs say dos attack icmp flood from different ips (C6300v2)

@FURRYe38  

Yeah I don't think the correctable and uncorrectable will be fixed. All my cables I can access are secure and in good shape and I doubt COX will run new line since the tech said it was fine. Even with those the connection has been fine since the tech left and haven't had any issues.

So I think the man issue of this thread is solved. 

But, to just confirm and recap the dos attacks and port scans that show up in the logs are fine and I shouldn't worry about them even if the log is showing the port they scanned i.e. SPT:xxxxx and DPT:xxxx correct? I haven't made any changes to the settings of the router/modem besides changing the password, the wifi names and passcodes, and the DNS server. 

 

So, if there isn't anything to worry about I really appreciate the help and answers you gave. Thank you!

 

Message 10 of 15
FURRYe38
Guru

Re: Internet dropping, logs say dos attack icmp flood from different ips (C6300v2)

Should be unless you notice something out of the ordinary. 

Might ask the ISP if they can change the WAN IP as one step to see if something happens. Most of the scans and attacks are seen across modems and routers. The logs just report that it took place and was stopped by the system. 

 

PW changes and such is good. 

 

Come back if you see something drastic happen or contact the ISP if this comes from the WAN side. Sometimes they can help in some places. 

 

Message 11 of 15
ButterSquatch
Aspirant

Re: Internet dropping, logs say dos attack icmp flood from different ips (C6300v2)

@FURRYe38 

 so just look every so often and if one of the attacks says the target is an IP on my network contact ISP or come back?

 

And will do Thank you!

Message 12 of 15
FURRYe38
Guru

Re: Internet dropping, logs say dos attack icmp flood from different ips (C6300v2)

Yes. You may see some IoT devices that can be a target. Also sometimes its those IoT devices that have a calling card back to the mothership as well. Something to keep in mind. 

Message 13 of 15
ButterSquatch
Aspirant

Re: Internet dropping, logs say dos attack icmp flood from different ips (C6300v2)

@FURRYe38  

Will do. Ill make sure to do my research if I get any.

Message 14 of 15
FURRYe38
Guru

Re: Internet dropping, logs say dos attack icmp flood from different ips (C6300v2)

Be sure to save off a back up configuration to file for safe keeping. Saves time if a reset is needed.
https://kb.netgear.com/24231/How-do-I-back-up-the-router-configuration-settings-on-my-Nighthawk-rout...
Enjoy. 📡

 

Message 15 of 15
Top Contributors
Discussion stats
  • 14 replies
  • 2763 views
  • 1 kudo
  • 2 in conversation
Announcements

Orbi WiFi 7