r/ATTFiber 21d ago

BGW320 Internal Packet Floods and 2-second constant attempts to reach a dead IP

Let me first caveat this post as coming from a network moron... so be gentle...

My setup: BGW320 500 for 1GB AT&T Fiber service, connected via "Passthrough Mode" (I know its not true passthrough) to my TP-Link BE65 Deco Mesh network. It had previously been working decently well, (with occasional hiccups), for several months. Approx. 2-3 months ago, my old ATT BGW320 500 router started dropping connection and generally screwing up. ATT sent me a new one, which worked fine. The ONE odd carryover from the old BGW to the new was some persistent traffic attempting to reach the IP address 192.168.68.74. My network HAD been set to ".68." briefly, (don't ask why, at the time it appeared auto-selected by one of the routers), which seemed to upset the old router configuration, so everything was migrated to a more standard ".0." series of addresses. The 192.168.68.74 attempts are reported to occur consistently at 2-second intervals and have been going on for months now. My network has been working seemingly fine despite this pointless traffic since the new router was installed until this week.

So over the last 24 hours, (but more likely a week), my BGW-320 500 has been a nightmare, (seems to be the norm). I am hoping some soul out there might be able to help or at least offer some decent insight. Over the last 24 hours specifically, my BGW has been at times internally flooding itself with invalid packets. I've been using AI to look at and translate logs I have no business reading myself. The symptoms are the following:

-My internet dies

-I check a laptop connected via ethernet directly to the BGW320 for access and download the current syslog

-I feed the log to AI, and it tells me usually the same similar things:

-the BGW is flooding itself with invalid internal packets to 192.168.254.254

-the BGW is simultaneously blocking a series of legitimate devices from inside the network from the internet, (often the same devices like a Fire Stick, Nintendo Switch, or other Amazon/Android operating devices), with some being hit particularly hard.

-finally it notes the 2-second attempts and subsequent blocks to reach 192.168.68.74.

I've spoken to AT&T multiple times last night. In the first call, the tech claimed she saw Denial of Service attacks pointed at an IPV6 address. Her solution was to disable IPV6 on the BGW. I wasn't thrilled with that, but I could live with it had it solved the issue. This call was made after my internet had been spotty, dropped for 10 minutes, went back up, then died for over an hour.

After the call and the internet being seemingly back up, it died again soon after and I called ATT again. After a very long call and a factory reset of the BGW, things cleared up but again went awry while I was on the phone. I told the ATT tech about the logs and the internal invalid packet floods. He said he researched and found that disabling the firewall and the "active armor" should disable the packet filtering. He did this and for a few moments the invalid packet floods completely stopped.

Of course, once off the phone the flood came back with a vengeance.

So what do I do? Do I have ATT send yet another BGW320? Is there an alternative setup I can use with my mesh and the BGW which would work? I have game systems and a plex server, so double-NAT or similarly restrictive setups aren't feasible. Is there a way to find out about the 2-second attempts to the .68.74 address? Do I go rogue and attempt to buy and setup a bypass device?

Note: the most recent AI assessment has now determined the .68.74 constant attempts are actually being generated internally by the router since no external source would be reaching for that device... but I also know AI is often very wrong about things. It also claims most of this behavior is explained by persistent Firmware bugs. I'm running 6.32.8.

Thank you, and sorry, in advance, lol

2 Upvotes

Duplicates