user_u6dx3g's profile

Contributor

 • 

34 Messages

Monday, August 5th, 2024 10:21 PM

Why is router reporting DoS attack on a different ip ?

I have a C7000v2 modem router. DNS is cloudflare (1.1.1.1). I see these dos attack logs in the router but they are not making any sense. Its from the dns to 98.42.123.84 which is an ip that is not part of the network. What is 98.42.123.84 ?

DoS attack: TCP- or UDP-based Port Scan] from 1.1.1.1, port 53 1 Mon Aug 05 13:37:57 2024 98.42.123.84:55487 1.1.1.1:53

I see multiple logs like these exactly same except the port# changes. There are several in an hour.

What does this mean ? Is anyone able to explain what might be going on here ?

Contributor

 • 

34 Messages

3 months ago

98.42.123.84:58472

98.42.123.84:61532

98.42.123.84:50952

..

every 15-20 mins in the router log. What the heck is going on ? Has anyone experienced anything like this ? Who or what is 98.42.123.84 ?

Contributor

 • 

34 Messages

3 months ago

Well looks like 98.42.123.84 is owned by Comcast and it is located nearby. But I would still like to understand what is this traffic and why is it needed and causing the router to panic ? 

@Xfinity_Support 

@XfinityOrlandoM

can you please help ?

Official Employee

 • 

1.4K Messages

Thanks for reaching out, user_u6dx3g! That defiantly doesn't make a whole lot of sense. Have you already checked your firewall settings or reached out to Netgear? 

 

I am an Official Xfinity Employee.
Official Employees are from multiple teams within Xfinity: CARE, Product, Leadership.
We ask that you post publicly so people with similar questions may benefit from the conversation.
Was your question answered? Please, mark a reply as the Accepted Answer.tick
forum icon

New to the Community?

Start Here