Jump to content

XR1000 Issues I have noticed


Recommended Posts

Hello all. 

first let me explain my setup. 
All external cables are cat 8, cables in the walls are cat7 with cat8 keystones on them. 
BT Open reach Modem MT992 > XR1000 (front of house)
Port 1 > XR500 (Access point) (back of house) > Port 2 > PS5,  Port 3 > TV
Port 2 > EX7000 (Access point) (middle of house)
Port 3 > PS4

I have reinstalled the most uptodate firmware on to the XR1000 incase this may of been the issue inc restarting the router and keeping the power off for 5mins. 
I boot up as Modem (2-3mins)  > XR1000 (2-3mins) > XR500 (2-3mins) > EX7000 (2-3mins)

I have guest WIFI set up on the XR1000 and XR500, the EX700 does not seem to have a Guest WIFI mod (to be far i thought this was part of the same range as nighthawk/Duma) 

1. The CPU usage seem high jumping around 80-99% even even low data being used (less then 1mb). after the reinstall of the firmware it has got a bit better. 
2. The device map list show a lot of devices offline. can you can see in the network snapshot and Duma IOS app shows devices online and i know some devices are online. I have also made sure IOS is not in Private WIFI address and so on. also the Duma apps does shows how the devices is connected correctly e.g WIFI/Cable and online/offline. Devices  connected to either the XR500 or EX700 if they show online they will show as on the lan (i am guessing this should be the way it work as going thought these that are connected to the XR1000 with a lan cable). 
3. traffic rules time seems to be out by an hour. I have check routers time and it shows the correct time but the rules do not activate till an hour after time E.G i would like to turn off Kais PS Pro at 9pm but i have to pick 8pm in the time for it to stop at 9pm (no big issue but still an issue) 
4. i have noticed some devices getting 2 IP addressed linked to them. (to try and fix this gave most devices a static IP address, ones on guest wifi do not have static IP)

Screenshot 2022-09-14 at 12.08.05.png

Screenshot 2022-09-14 at 12.08.37.png

Screenshot 2022-09-14 at 12.10.49.png

Screenshot 2022-09-14 at 12.24.53.png

Screenshot 2022-09-14 at 12.28.30.png

04807876-C4E0-499F-AE81-6B4389AD12A7_1_201_a.jpeg

448BBCBC-3C15-49F4-B252-0A68AD7F5714_1_201_a.jpeg

D04544CF-BA73-45B3-A6C5-7243B1D66990_1_201_a.jpeg

Link to comment
Share on other sites

  • Administrators

Welcome to the forum!

To answer your questions/concerns:

  1. Did you do a factory reset after you upgraded to the latest firmware? If not that is highly recommended. Do you have Armor enabled?
  2. They will show connected via ethernet because technically the router is receiving/sending traffic via ethernet to those devices. In regards to the offline aspect I believe that is something we're looking at fine tuning, it's due to the APs basically, a reboot of the router should resolve it in most cases.
  3. Change the NTP server to 0.uk.pool.ntp.org and disable DST and apply, does it work better then?
  4. Could you provide a screenshot of an example of a device receiving two IP addresses? Likely what has happened is that DHCP has assigned a different IP when the lease renewed, the old one won't be used and would be removed after a reboot.
Link to comment
Share on other sites

1. got router as new. upgraded to to latest version and seem to have some issue so reinstalled the firmware. have not done a factory reset. i am planning to do this over the weekend possible tomorrow.  but have a BT engineer out tomorrow as the modem (BT Open reach Modem MT992) seem to be loosing connection to the internet for 2-3mins before it reconnects. the XR1000 router seems to running ok so taking it is a modem issue.  Armour was enabled the free trail ran out a wile back and is now disabled(see screenshot). 

2. a reboot off the router(and all other devices) does not help with devices offline.  to note most devices will be connecting to XR500/
EX7000

3. I have added these settings but now the time on the router is out by an hour. (see screenshot)

4. the 2x IP address i have added 3 screenshots 1x iPhone, 1x Ipad, 1x PS4 (they all on the guest WIFI)

Screenshot 2022-09-15 at 22.25.12.png

Screenshot 2022-09-15 at 22.27.36.png

Screenshot 2022-09-15 at 22.30.21.png

Screenshot 2022-09-15 at 22.30.45.png

Screenshot 2022-09-15 at 22.31.03.png

Link to comment
Share on other sites

  • Administrators

Okay re-enable DST and see if it's correct with the new NTP server please. So the fe80 is a link local IPv6 address, you can ignore that, your connection isn't using IPv6 but as the options are enabled that's why you're getting it, you can ignore it completely, it won't have any affect. As for the other addresses that will be what I mentioned previously, if you give each device a reserved IP and reboot then it will just have the one & the link local IPv6 address (unless you disable IPv6 in LAN/WAN) but you can ignore it, it won't cause any issues. Setting the reserved IPs may help with them showing offline but otherwise it will be due to using the APs, also if traffic isn't going through a device it will very quickly switch to offline even if it's still connected.

Link to comment
Share on other sites

9 hours ago, Netduma Fraser said:

Okay re-enable DST and see if it's correct with the new NTP server please. So the fe80 is a link local IPv6 address, you can ignore that, your connection isn't using IPv6 but as the options are enabled that's why you're getting it, you can ignore it completely, it won't have any affect. As for the other addresses that will be what I mentioned previously, if you give each device a reserved IP and reboot then it will just have the one & the link local IPv6 address (unless you disable IPv6 in LAN/WAN) but you can ignore it, it won't cause any issues. Setting the reserved IPs may help with them showing offline but otherwise it will be due to using the APs, also if traffic isn't going through a device it will very quickly switch to offline even if it's still connected.

Hello

The time is now look ok in the router then adding the DST back on. but will not know if this fixes the issue till tonight at 8-9pm (UK time) 

Checked the router and cannot see anyway to disable IPv6 in the router in LAN/WAN page can only see a option in option > IPV6 and it shows as disabled. as you said not a big deal as will not affect anything. 

As the Offline Items the Duma and Nighthawk app show the items online and the items e.g laptop, iphone , Amazon fire tablet can all be streaming Netflix. prime or so on and it will still show offline on the website. 

The BT engineer has been out and did not find any issue with their line or modem (BT Open reach Modem MT992). so now wondering if it may be the XR1000 giving the modem an issue. Has there been any cases where the Xr1000 cosed a modem to drop internet? 

 

 

Screenshot 2022-09-16 at 09.41.05.png

Screenshot 2022-09-16 at 09.43.51.png

Link to comment
Share on other sites

  • Administrators

Let us know if your Traffic rule works better later! Okay so you can ignore the IPv6 address then that's fine. I think it will be the APs then as to why it's not able to properly detect whether the devices are online or not, does Traffic Prioritization still work for a device it thinks is offline? If you could grab the log from the System Information page when the disconnect happens I can look into it further.

Link to comment
Share on other sites

1 hour ago, Netduma Fraser said:

Let us know if your Traffic rule works better later! Okay so you can ignore the IPv6 address then that's fine. I think it will be the APs then as to why it's not able to properly detect whether the devices are online or not, does Traffic Prioritization still work for a device it thinks is offline? If you could grab the log from the System Information page when the disconnect happens I can look into it further.


Traffic rules i will not be able to tell if they work till tonight. 
I am not sure if Traffic Prioritization are working or not. 
PS4 is connect to Lan port 3 on xr1000
PS5 is Connected to Lan on XR500 that is connected to lan on XR1000
Will post new post with the logs in soon

 

Screenshot 2022-09-16 at 13.38.44.png

Screenshot 2022-09-16 at 13.40.41.png

Link to comment
Share on other sites

Last couple of days when internet has dropped. i cannot remember when i last cleared the logs in the router. 
Not sure if time in logs will be same time or an hour out. 
14/09/22 - 22:13 pm Reconnected 22:15 pm
15/09/22 - 09:37 am reconnected 09:40 am
15/09/22 - 10:05 am reconnected 10:08 am
15/09/22 - 10:17 am reconnected 10:19 am
15/09/22 - 10:20 am reconnected 10:22 am
15/09/22 - 10:25 am reconnected 10:27 am
16/09/22 - 08:20 am BT engineer came out till 08:50 am no issue found on the line
16/09/22 - 09:08 am reconnected 09:10 am
16/09/22 - 10:09 am reconnected 10:11 am
16/09/22 - 12:48 pm reconnected 12:50 pm

Logs.txt

Link to comment
Share on other sites

Just had a drop out there at 
16/09/22 - 13:58 pm reconnected 14:00 pm
Only think showing in logs was 

[DoS attack: Fraggle Attack] from source UNKNOWN,port 443 Friday, Sep 16,2022 13:59:26

once it was reconnected these showed up  (to me these looks like false alert to me)
[DoS attack: ACK Scan] from source 74.112.186.144,port 443 Friday, Sep 16,2022 14:07:10
[DoS attack: ACK Scan] from source 130.211.16.53,port 443 Friday, Sep 16,2022 14:07:08
[DoS attack: ACK Scan] from source 130.211.26.229,port 443 Friday, Sep 16,2022 14:07:07
[DoS attack: ACK Scan] from source 130.211.16.53,port 443 Friday, Sep 16,2022 14:07:06
[DoS attack: ACK Scan] from source 130.211.26.229,port 443 Friday, Sep 16,2022 14:07:06
[DoS attack: ACK Scan] from source 34.117.237.239,port 443 Friday, Sep 16,2022 14:06:47
[DoS attack: ACK Scan] from source 2.20.70.9,port 443 Friday, Sep 16,2022 14:05:16
[DoS attack: ACK Scan] from source 2.20.70.8,port 443 Friday, Sep 16,2022 14:05:14
[DoS attack: ACK Scan] from source 104.21.36.185,port 443 Friday, Sep 16,2022 14:03:45
[DoS attack: ACK Scan] from source 104.21.36.185,port 443 Friday, Sep 16,2022 14:03:35
[DoS attack: ACK Scan] from source 54.228.171.0,port 443 Friday, Sep 16,2022 14:02:08
[DoS attack: ACK Scan] from source 18.164.68.29,port 80 Friday, Sep 16,2022 14:01:08
[DoS attack: ACK Scan] from source 64.207.199.18,port 4287 Friday, Sep 16,2022 14:00:46
[DoS attack: ACK Scan] from source 64.207.199.172,port 4287 Friday, Sep 16,2022 14:00:37
[DoS attack: ACK Scan] from source 64.207.199.115,port 4287 Friday, Sep 16,2022 14:00:37
[DoS attack: ACK Scan] from source 64.207.199.172,port 4287 Friday, Sep 16,2022 14:00:36
[DoS attack: ACK Scan] from source 64.207.199.115,port 4287 Friday, Sep 16,2022 14:00:36
[DoS attack: ACK Scan] from source 20.90.152.133,port 443 Friday, Sep 16,2022 14:00:35

 

 

P.S can we get a Access Point/Extender Icon added :P 

Link to comment
Share on other sites

  • Administrators

You don't need the Traffic Controller rules for the consoles, it's more of a parental control feature so the rules you've added essentially aren't doing anything as it's already allowed, it could also be the reason why it doesn't appear Traffic Prioritization is working. Also remove the rules you've added on Traffic Prio, DumaOS Classified Games will prioritize it automatically.

Thank you for the logs, they've been quite enlightening, is there a pattern to what you're doing on the internet at the time when you get a disconnect? As it appears you're getting a DoS attack every time you get disconnected.

We could add those icons but technically the router doesn't actually see the AP, its transparent to it.

Link to comment
Share on other sites

53 minutes ago, Netduma Fraser said:

You don't need the Traffic Controller rules for the consoles, it's more of a parental control feature so the rules you've added essentially aren't doing anything as it's already allowed, it could also be the reason why it doesn't appear Traffic Prioritization is working. Also remove the rules you've added on Traffic Prio, DumaOS Classified Games will prioritize it automatically.

Thank you for the logs, they've been quite enlightening, is there a pattern to what you're doing on the internet at the time when you get a disconnect? As it appears you're getting a DoS attack every time you get disconnected.

We could add those icons but technically the router doesn't actually see the AP, its transparent to it.

OK i have removed Traffic Controller rules for the consoles and also removed Traffic Prioritization so only thing in there is DumaOS Classified Games and Work at home. 

well this week prob the best week to see where the issue lies. as my GF is away.  
so around this time i am the only person in the house. working from home. My machine connected to 2x different VPNs and we also use ProxyCap (new proxy tool that I hate but was getting the issue before this tool OpenSockets). 
I also may have Netflix playing on the TV in the background and my have to use my phone now and again. there will be other devices connected but not in use. 
also u supply my upstair access to internet on the guest WIFI so not sure of what they are doing (they don't own a computer/laptop but have Phones, tablets and 1xPS4) but again at the time of this happening all her kids are also at school. so it is just the mum home alone so mainly on her phone. 
to note the work laptop is always on in the background. so tonight i will turn it fully off so. 

 

Below if the full logs of dropouts that i have noticed
14/08/22 - 18:20 pm
16/08/22 - 09:40 am
18/08/22 - 10:10 am
20/08/22 - 00:00 am
23/08/22 - 11:06 am
25/08/22 - 09:19 am
25/08/22 - 21:00 pm
26/08/22 - 5:50 am
[DoS attack: ACK Scan] from source 40.100.174.213,port 24997 Friday, Aug 26,2022 05:47:04
[DoS attack: ACK Scan] from source 40.100.174.213,port 24997 Friday, Aug 26,2022 05:47:04
[DoS attack: ACK Scan] from source 40.100.174.213,port 59139 Friday, Aug 26,2022 05:46:35
[DoS attack: ACK Scan] from source 40.100.174.213,port 39531 Friday, Aug 26,2022 05:46:35
[DoS attack: ACK Scan] from source 40.100.174.213,port 59139 Friday, Aug 26,2022 05:46:35
[DoS attack: ACK Scan] from source 40.100.174.213,port 39531 Friday, Aug 26,2022 05:46:26
[DoS attack: ACK Scan] from source 40.100.174.213,port 39531 Friday, Aug 26,2022 05:46:26
[DoS attack: ACK Scan] from source 40.100.174.213,port 23952 Friday, Aug 26,2022 05:46:20
[DoS attack: ACK Scan] from source 40.100.174.213,port 23952 Friday, Aug 26,2022 05:46:19

26/08/22 - 10:10 am
[DoS attack: ACK Scan] from source 17.253.77.202,port 80 Friday, Aug 26,2022 10:02:05
[DoS attack: ACK Scan] from source 17.253.77.202,port 80 Friday, Aug 26,2022 10:02:05
[DoS attack: ACK Scan] from source 17.36.202.111,port 443 Friday, Aug 26,2022 10:00:16

26:08/22 - 14:52 pm - Reconnected 14:56 pm
[DoS attack: RST Scan] from source 2.18.97.126,port 443 Friday, Aug 26,2022 14:43:42
[DoS attack: RST Scan] from source 2.18.97.126,port 443 Friday, Aug 26,2022 14:43:42
28/08/22 - 11:10 am
31/08/22 - 9:55 am - Reconnected 9:58 am/
31/08/22 - 10:00 am - Reconnected 10:02 am
31/08/22 - 20:26 am
31/08/22 - 21:22 am
01/09/22 - 9:00 am
01/09/22 - 9:30 am may be engineer test
01/09/22 - 9:40 am may be engineer test
01/09/22 - 9:47 am may be engineer test
01/09/22 - 11:00 am engineer finished line ok and replaced modem. He did say the connection in the box outside seem loose and did cut and replace the connection. (have sins been told this BT engineer is like the top dog of the guys and knows his stuff)

01/09/22 - 14:33 am
02/09/22 - 10:32 am
05/09/22 - 01:22 am Reconnected  01:24 am
05/09/22 - 09:55 am
11/09/22 - 20:37 pm Reconnected 20:40 pm
11/09/22 - 20:44 pm Reconnected 20:47 pm
13/09/22 - 13:24 pm
14/09/22 - 09:16 am Reconnected 09:18 am
14/09/22 - 09:20 am Reconnected 09:22 am
14/09/22 - 09:24 am Reconnected 09:28 am
14/09/22 - 09:29 am Reconnected 09:32 am
14/09/22 - 09:33 am Reconnected 09:35 am
14/09/22 - 09:47 am Reconnected 09:49 am
14/09/22 - 09:53 am Reconnected 09:55 am
14/09/22 - 09:57 am Reconnected 09:59 am
14/09/22 - 10:12 am Reconnected 10:14 am
14/09/22 - 10:15 am - Rebooted modem (powers off for 1mins), powered on at 10:16 am.  Reconnected 10:18 am
14/09/22 - 10:28 am Reconnected 10:30 am (Rebooted modem and router - Change modem cable to socket)
14/09/22 - 10:28 am Reconnected 10:30 am
14/09/22 - 11:00 am re-flashed the firmware on the router
14/09/22 - 14:00 pm Reconnected 14:02 pm
14/09/22 - 17:20 pm
14/09/22 - 22:13 pm Reconnected 22:15 pm
15/09/22 - 09:37 am reconnected 09:40 am
15/09/22 - 10:05 am reconnected 10:08 am
15/09/22 - 10:17 am reconnected 10:19 am
15/09/22 - 10:20 am reconnected 10:22 am
15/09/22 - 10:25 am reconnected 10:27 am
16/09/22 - 08:20 am BT engineer came out till 08:50 am no issue found.
16/09/22 - 09:08 am reconnected 09:10 am
16/09/22 - 10:09 am reconnected 10:11 am
16/09/22 - 12:48 pm reconnected 12:50 pm
16/09/22 - 13:58 pm reconnected 14:00 pm

Link to comment
Share on other sites

  • 2 weeks later...
On 9/16/2022 at 4:38 PM, Netduma Fraser said:

Interesting, it could be the VPNs, do let us know your findings but I'm pretty sure there will be a pattern to it.

So internet issue dropping out does not seem to be linked to any router or machine issue as the modem it self loses connection with nothin plugged in. 
has phone line inside the house replaced, has a new cable installed from the telegraph pole to the house and the 2 pair of cables changed from the telegraph pole  to the exchange and still have the same issue. now the drops out happen 9-5 (manly down). 


Back to the time on the router to turns out there is a 2nd area to change the time on the router that affected the time.  so the NTP Settings in Admin settings does not seem to affect the router time.
 

Screenshot 2022-09-26 at 23.29.47.png

Screenshot 2022-09-26 at 23.34.53.png

Link to comment
Share on other sites

On 9/27/2022 at 12:11 AM, Netduma Fraser said:

Sorry to hear the issues are persisting, hopefully the ISP can figure it out. Ah yes, well done on figuring it out, looks like we need to make those sync up, thanks for posting your solution!

The drop out seem to be linked to ISP.
Has the Openreach out and they installed a new phone cable inside the house, a new Cable from the pole to the house and was still having issue and the Openreach guy saying it is down to the line underground cannot handle the speeds. but the issue would only happened from 9-5 for a week then changed from 12-4pm the following week. so i got them to send out another guy and i told him to change my ports at the exchange (this involves a call to India) he was supported that i new about this.  and this seem to have fixed the issue not had one drop out in 4 days also at the same time i also added nextDNS to my setup and what a difference it makes. 

 

CPU usage seem to have fixed it self after doing a reformat of the router now stays mainly under 70%


Hope to see some updated with device maping to help show devices online with AC points 
Also hope you add what something like what NextDNS has like Traffic Destination so we can see where traffic is coming from also there logs page is nice where u can see what pages have been looked up and what one have been blocked (and by what ad list). 


 

Screenshot 2022-10-02 at 19.36.11.png

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
 Share

×
×
  • Create New...