Orbi WiFi 7 RBE973
Reply

Nighthawk Blocking whole network DNS

C0NN0RAD0
Follower

Nighthawk Blocking whole network DNS

Hi Forums Goers,

 

I Am desperately reaching out here as I wasn't too sure where else to start, our family home has a Nighthawk X6 AC3200 Router we got it because our ISP router wasn't very good and caused problems a lot of the time.

 

Within the past year or two we have had a load of issues where suddenly the connection for the whole of the house is interrupted usually for a period of half an hour or longer it tends to be random periods of times, sometimes even constantly until the router is restarted.

 

Specifically the problem we have is all the devices go down as if we just disconnected the WAN cable from the router, I can't speak to if this issue is just for AP connected devices or LAN Hardwired ones too. Services like Youtube, Netflix, Facebook all stop working for EVERYONE on the network. What is interesting is smart home devices (low bandwidth) like LED strips still work, Alexa's work once in a blue moon when this is happening. But if you connect VIA a VPN your connection works fine, full speeds perfectly.

 

I only know this as I use VPNS but no one else in house does, this issue always arises when a few of us come back to the house after being away for a few days, we have Apple Devices, the network is dominated primarily with Android Smart phones and regular smart Tv's, Xbox's Etc. It constantly happens when we are here at random times of the day sometimes a few times a day it ruins the network for all and causes havoc in the house.

 

Apparently it doesn't happen when we aren't here with our Apple devices.

 

We use either Armor or Circle I believe it is to protect the network and I know this blocks certain traffic like Snapchat occasionally (lets Facebook, twitter through etc) and would block basic sites like adult sites, gambling, etc. 

 

My thought is something the Apple devices use to communicate to Apple servers is causing it to be mass blocked (network blocking 5 or 6 devices) all at once causing a miniature DOS (Denial of service) attack In the network shutting it down where devices can't make DNS requests (google.com) but can use VPN's etc which is so unusual.

 

I Know Apple use Private Relay and our network blocks VPN sites like Surfshark and Nord if you try visit them, doesn't give me a web page just cuts the traffic and generic can't connect to this server page pops up. 

 

Technical observations:

Fing (Network manager) when this happens gives me the following messages in diagnostics "DNS Resolution isn't working on this network"

I Have family strong luck most of the time when I change the DNS of my devices to 1.1.1.1 (Cloudflare) when the outage is occurring and sometimes I don't.

As mentioned VPN's completely dodge the problem and let all traffic and device work perfectly.

 

Apparently the Router is up to date.

 

Really hope someone can help this appears to be quite a unusual and uncommon issue.

 

Thank you.

Message 1 of 3

Re: Nighthawk Blocking whole network DNS

First question, what is the modem/gateway that connects your router to the internet?

 

Next one, what firmware version do you have on the device?

A number is more useful than "the latest". (It may not be by the time people read this.) There can also be newer versions, or "hot fixes", that do not show up if you check for new firmware in the browser interface.

Message 2 of 3
ClarkRay82
Initiate

Re: Nighthawk Blocking whole network DNS

I Would believe that the router sounds to have Circle (Strong parental controls) active or Netgear Armour (focuses more on protecting network from threats like Phishing, Attacks, Scam Mail, etc) which both serve functions of protecting network / users via blocking certain services and websites. Also the probability there are just general parental controls enabled on the router.

 

Either way these are all accessible in the Netgear App you use to manage router and via the router interface in your browser.

 

Where i think this relates to your problem is if theres settings active to block adult content or VPN's and other types of miscellaneous services it is very likely (because you mentioned that it only happens when an abundance of Apple devices come back onto the network) that a sort of mini DDOS or DOS (where the network is overloaded and suffers) is happening because it is blocking so many requests from all these devices.

 

It is all very likely these were activated when Apple started closing down on privacy and tracking and their Private Relay feature as Apple devices connect through any of Apples Domains so the network is likely now told to block a large majority of Apple's traffic. 

 

It is likely even for things like iMessage, Facetime, Safari, Mail, Gamecentre, App Store, Apple music that the network might be deeming this traffic as hostile as its told to block VPN's etc (which is essentially what Apples Private Relay is) as the devices connect through any of Apples services.

 

Example is the domains Apple Devices use to connect to Private Relay:

mask.icloud.com
mask-h2.icloud.com

But as i said can communicate through Apples other domains too.

 

If you was to add these domains as an exception it may fix your issue, but you said you've disabled Private Relay and its still occuring, so add exceptions for Apple's other Domains too that your Apple Devices make requests to. You can also likely see these being flagged by the router.

 

time.apple.com

*.push.apple.com

icloud.com

Apple.com

*.itunes.apple.com

itunes.apple.com

itunes.com

*.apps.apple.com (might cause network issues if updating a lot of apps automatically overnight)

appleid.apple.com

*.apple-cloudkit.com

 

"If your firewall supports using hostnames, you might be able to use most Apple services above by allowing outbound connections to *.apple.com. If your firewall can only be configured with IP addresses, allow outbound connections to 17.0.0.0/8. The entire 17.0.0.0/8 address block is assigned to Apple."

 

You can view Apple's whole article of Domains here but i truly believe that how you described this issue and being Apple Devices that this should 99% fix this issue.

 

That is my most in-depth answer yet and i really hope it helps you!

 

Message 3 of 3
Top Contributors
Discussion stats
  • 2 replies
  • 697 views
  • 1 kudo
  • 3 in conversation
Announcements

Orbi WiFi 7