Orbi WiFi 7 RBE973
Reply

C3700 DoS, Port Scan, Time, Firmware

C37
Aspirant
Aspirant

C3700 DoS, Port Scan, Time, Firmware

I have five questions.

 

1. Firmware update. My current versiaon is V2.02.23. From what I can tell, this is the latest version available, but I'm worried I might be missing something. The support site says updates will be pushed down from my ISP. However, My ISP (Xfinity) told me I would have to contact the manufacturer to update. The downloads site seems to have it listed as the most recent version. Can anyone confirm?

 

2. Time. The time has been set incorrectly since I got it a few years ago. It is set to 24 hr MST apparently, and I am in CST. So not only do I have to account for 24 hr time, but I also have to account for the extra hour, and it is just annoying and unnecessarily confusing at times. However, I see no option anywhere to change it. I found a post that said it can be changed in scheduling, but that only allows to set a time to schedule for blocking sites or services. It doesn't actually change the system time. I also found a post that said it is set from the ISP. However again, Xfinity did not seem to have that option. They directed me to factory reset, which I knew wouldn't help, but I did it anyway, because I also wanted to reconfigure everything. Any advice at all on how to correct the time?

 

3. Wireless Network Mode. The default is 300, manual says 145, and interface help says 300, with 145 listed as neighbor friendly with a speed of up to 145 Mbps in the presence of neighboring wireless networks. The first in a series of inconsistencies between default settings and recommended default settings in the manual and interface help. I only have a 50 Mbps speed. My question is does this affect ISP speed at all or does it affect only LAN transmission rates? I live in an apartment complex, so should I use 145? I can't seem to tell much difference in testing.

 

4. Wireless Security Options. The default setting is WPA2. However, the manual says the default is WPA-PSK [TKIP] + WPA2-PSK [AES]. Could it be that a firmware update changed the default setting to WPA2 since it has been awhile, and most devices are supporting it now?

 

5. Disable Port Scan and DoS Protection. This is my most important issue. This setting is checked by default, meaning the protection is disabled. However, the manual and the interface help says to only disable in special circumstances. There are a lot of posts about issues with this setting causing false alarms and constant logging. It seems to do this to me. When the protection is enabled, I get a lot of logs for port scan, DoS attacks, and SYN flood attacks. They mostly point to DNS servers (Comcast, however, it did pop some briefly for Google as well during troubleshooting). So I'm wondering if the issue was realized and so widespread that it was set to disable in a firmware update, but the manual and interface help was not updated to reflect that. If not, then what is the point of the setting? It seems to cause more issues than help. Any more detailed advice than what I've already found is appreciated.

 

It seems that a lot of these settings have been updated from their original default settings going by the manual and some of the interface help info, and the manual and interface help info were not updated to reflect. If anyone has any other general advice for this model or knows of any conflicts due to update, please let me know.

 

Just for reference UPnP is off (was on), DNS is set to Cloudfare since reconfig (was Comcast prior), I only have less than ten devices at a time, rarely online game, do not download a lot, mostly stream and browse

Model: C3700|N600 Cable Gateway Docsis 3.0
Message 1 of 2
FURRYe38
Guru

Re: C3700 DoS, Port Scan, Time, Firmware


@C37 wrote:

I have five questions.

 

1. Firmware update. My current versiaon is V2.02.23. From what I can tell, this is the latest version available, but I'm worried I might be missing something. The support site says updates will be pushed down from my ISP. However, My ISP (Xfinity) told me I would have to contact the manufacturer to update. The downloads site seems to have it listed as the most recent version. Can anyone confirm?

ONLY ISP can update FW on cable modems. NG develops FW for the modems however has to send it to the ISPs to get tested and certified on there networks prior to them pushing FW to users modems. Only cable ISPs can do this. 

 

2. Time. The time has been set incorrectly since I got it a few years ago. It is set to 24 hr MST apparently, and I am in CST. So not only do I have to account for 24 hr time, but I also have to account for the extra hour, and it is just annoying and unnecessarily confusing at times. However, I see no option anywhere to change it. I found a post that said it can be changed in scheduling, but that only allows to set a time to schedule for blocking sites or services. It doesn't actually change the system time. I also found a post that said it is set from the ISP. However again, Xfinity did not seem to have that option. They directed me to factory reset, which I knew wouldn't help, but I did it anyway, because I also wanted to reconfigure everything. Any advice at all on how to correct the time?

Try changing the time zone using a web browser, Firefox or IE11. 

Ask the ISP to check the configuration file on the modem as well.

 

3. Wireless Network Mode. The default is 300, manual says 145, and interface help says 300, with 145 listed as neighbor friendly with a speed of up to 145 Mbps in the presence of neighboring wireless networks. The first in a series of inconsistencies between default settings and recommended default settings in the manual and interface help. I only have a 50 Mbps speed. My question is does this affect ISP speed at all or does it affect only LAN transmission rates? I live in an apartment complex, so should I use 145? I can't seem to tell much difference in testing. Only  connection rates between the wifi radios on the modem and wifi devices that connect to the modem only. 

 

4. Wireless Security Options. The default setting is WPA2. However, the manual says the default is WPA-PSK [TKIP] + WPA2-PSK [AES]. Could it be that a firmware update changed the default setting to WPA2 since it has been awhile, and most devices are supporting it now?

There should be a WPA2 and AES only setting that you can change took. Having mixed modes is for backewards compatibility with older wifi devices. But you don't have to use mixed mode.

 

5. Disable Port Scan and DoS Protection. This is my most important issue. This setting is checked by default, meaning the protection is disabled. However, the manual and the interface help says to only disable in special circumstances. There are a lot of posts about issues with this setting causing false alarms and constant logging. It seems to do this to me. When the protection is enabled, I get a lot of logs for port scan, DoS attacks, and SYN flood attacks. They mostly point to DNS servers (Comcast, however, it did pop some briefly for Google as well during troubleshooting). So I'm wondering if the issue was realized and so widespread that it was set to disable in a firmware update, but the manual and interface help was not updated to reflect that. If not, then what is the point of the setting? It seems to cause more issues than help. Any more detailed advice than what I've already found is appreciated.

You can enable these if you wish. Logging will see various entries of items which are normal to see on a ISP service. Means logging is working.

 

It seems that a lot of these settings have been updated from their original default settings going by the manual and some of the interface help info, and the manual and interface help info were not updated to reflect. If anyone has any other general advice for this model or knows of any conflicts due to update, please let me know.

Changes may have been implemented in recent versions of FW since the modem and user manual first came out. So there maybe some differences seen. 

 

Just for reference UPnP is off (was on), DNS is set to Cloudfare since reconfig (was Comcast prior), I only have less than ten devices at a time, rarely online game, do not download a lot, mostly stream and browse.

Thats ok too. I never had a problem with uPnP whatsoever. 

 


 

Message 2 of 2
Discussion stats
  • 1 reply
  • 458 views
  • 1 kudo
  • 2 in conversation
Announcements

Orbi WiFi 7