Jump to content

"LAN access from remote" appearing in logs, what is this?


Recommended Posts

Posted

Support,

 

For several weeks or longer I have been seeing "LAN access from remote" in my network's logs with a source IP from a specific port to a specific static IP and port of a device on my network. I have the device unplugged from the LAN ports and I am still receiving this message even though the device is "wired" in it's specific settings. I do not have any "remote" connection setup that I am aware of, and this message commonly shows up between "DoS Attack" messages.

 

Not sure what is going on here, but I would like to know if I am under attack, if there is more I can do, and if there is any type of help section available that I can use to understand the following:

 

"DoS Attack": when it should be recognized as an issue on my network?

"skiped spike rrt": why do I see this often and why do I get serious in-game lag when it occurs? What is it?

"LAN access from remote": no idea if this is normal or not.

 

Posted

Support,

 

For several weeks or longer I have been seeing "LAN access from remote" in my network's logs with a source IP from a specific port to a specific static IP and port of a device on my network. I have the device unplugged from the LAN ports and I am still receiving this message even though the device is "wired" in it's specific settings. I do not have any "remote" connection setup that I am aware of, and this message commonly shows up between "DoS Attack" messages.

 

Not sure what is going on here, but I would like to know if I am under attack, if there is more I can do, and if there is any type of help section available that I can use to understand the following:

 

"DoS Attack": when it should be recognized as an issue on my network?

"skiped spike rrt": why do I see this often and why do I get serious in-game lag when it occurs? What is it?

"LAN access from remote": no idea if this is normal or not.

March 23rd, I noticed a string of these DoS anomalies but my network was fine. Another thing I'm suspecting friggles.... Did you configure your XR500 for firmware auto-update under Settings>Administration?

 

That week I updated to the latest fw build was when I noticed a "LAN access from remote" ...My guess is that could've been the router communicating with netgear receiving the update, because shortly therafter... My router restarted by itself.

 

Everything's been fine ever since the update. I will continue backlogging, as anyone should.

  • Administrators
Posted

The log is for Developers rather than for customer self diagnosis. The entries you're seeing are absolutely fine. 

Posted

Thank you, Fraser.

 

Other than experiencing noticeable changes in internet service that are common during an actual DoS attack, do you have any examples of a DoS attack in the router logs? Or do we only bring it up if we are there to witness the attack and the slowed internet service that may be associated with it.

  • Administrators
Posted

Only bring it up if it appears you've actually been the target of a DDoS attack i.e. very slow internet, complete disconnects etc.

  • 2 years later...
Posted

I know this is an old topic, however, I just wanted to make sure I was ok, yesterday I forwarded ports for modern warfare. I did not check logs prior to doing this, so now Im a bit thrown off. I have numerous [LAN access from remote] from various ip addresses to my PC. a few DoS attack: Fraggle Attack all from the same source. 96.120.120.105 port 59074 which looks to be comcast?

  • Administrators
Posted

Do you have Comcast as an ISP? I think it should be fine because if you don't have remote access enabled which I assume you don't as it's disabled by default then there is no way anyone could access your router interface.

Posted

I do have Comcast, however, I’m concerned about the various other ip’s hitting only my desktop. I guess I just thought it was odd. I deleted all the forwarded ports but the ips keep coming. Some from Russia, LA, UK. UK, I believe is the traffic with the forum. The others I’m not sure.

Posted

It’s pretty normal to see port scans from all over the place, netgear routers are known for this. Mine shows a lot of attacks and I happily carry on. 

  • Administrators
Posted

I've got quite a few in my log as well but I haven't had any issues, as Newfie said it's a known occurrence on Netgear routers. There hasn't been one time where this has been a legitimate cause for concern yet.

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...