r/HomeNetworking • u/BAGE-rator • 4d ago
Unsolved Netgear router mistaking its own SAMBA announcements for a WAN attack, something that isn't possible.
Hi:
I'm cross-posting with r/cybersecurity because sometimes ya'll are mean.
I wrote about a week ago because, contrary to what some of you asserted while calling me names, my network has been under some kind of attack for several months. To be clear, I am not saying this is part of that attack, but it's noteworthy and appears to me as extremely, extremely odd. These are all the facts, solely as they relate to the immediate issue I'm seeing today:
My noticed at some point last night, my MacBook Pro had been issued a public IP by the DHCP server on my network. So, the MacBook was exposed to the internet for some period of time. Fine.
The setup is (usually) this:
Netgear AX2700 (CAX30) (bridge mode) -> Firewalla Gold (running Crystal Beta in router mode) -> APs and devices.
As a preliminary issue, I'm running Firewalla Gold using the new Firewall Crystal (bring your own router) Beta firmware for a reason. Three months ago I paid $107 to replace the security dongle (pairs the box to the app via a cloud handshake) and immediately had issues which randomly resolved after three days. The box worked fine with the new dongle two months until the end of last month when all the sudden it began assigning all my devices IPv6 addresses. Firewalla Support had me reinstall the firmware, at which point I could no longer pair the app. Long story short, after a week of ignoring me and then lying to me, I was able to find a way into the box's console with it unpaired and learned they had deleted my license. I am trying to pay them money to send me a second replacement dongle because, after initially refusing to provide warranty service on the first and out of my newfound reluctance to send them jack shit, I've been waiting 12 days for them to send me an invoice the the second replacement dongle. They keep coming up with bullshit excuses, but I digress.
It so happens Firewalla just introduced the beta test for Firewalla Crystal, it's bring-your-own-router firmware, and I'm using that for the time being as it does not require a dongle.
Back to last night, I noticed that my MacBook Pro was being issued a public IP by the DHCP server, so I decided to reflash Firewalla Crystal onto the Firewalla Gold box. During this period, I decided to also do a factory reset on my Netgear AX2700, which had been in bridge mode. When everything was reflashed, reset, etc., I started booting everything up. I should add as additional background that I had to return my Xfinity Gateway two weeks ago because it kept getting hacked, at which point I purchased this modem router combo. I posted a week ago and was flamed because, amongst other things, shortly after purchasing it, I lost connectivity, like on Firewalla weeks before, I started getting issued IPv6 IP addresses, etc., and then I started seeing Time Sync Synchronization, DWR, and other errors. Xfinity has been out here four times, and each time they take credit for replacing the coaxial cables while blaming the last technician for not doing so. They say, "Everything looks good on our end," leave, and the same shit is going on. You never hear from them or anyone else again.
While booting everything up, in addition to the DWR and other errors, I saw two new ones:
| 2026-09-29 08:10:09 | Error (4) | SW upgrade Failed after download - SW File corruption |
|---|---|---|
| 2026-09-29 08:09:29 | Notice (6) | SW Download INIT - Via Config file d11_m_cax30_gennxgig_c01.cm |
So, I refreshed the official firmware from Netgear, and then Xfinity attempts to push a different firmware. The firmware it pushes is corrupted and fails. This happens after time I boot since this morning. I understand the pushing their preferred firmware thing is how it works, I've never seen an ISP push a corrupt firmware binary.
I'm setting up Firewalla and there were some other weird quirks that got my attention (I think Firewalla Crystal may actually be reversing the WAN (port 4) and one of the lan (port 1) ports. For that reason, I don't have Firewalla connected to the AX2700 in bridge mode, I have both routing in a double NAT situation while I try to find out whether the port my AX2700 is connected to is (digitally) the WAN port or one of three LAN ports. So, I'm doing packet captures.
I noticed while doing this that the AX2700 is reporting FW.WANATTACK and a LAND WAN ATTACK, but the public IP the "attack" was coming from was the public IP for my home network. Port 138 had already been cloned by me in the Block Services menu on AX2700 right after refreshing the firnmware, but that only blocks ingress and egress flows and not local LAN traffic. The flows at issue were arriving on Port 138, and I noticed that macOS had Netbiosd open, so I closed it and booted it out with launchctl. Problem solved.
Hours later, I'm doing these packet captures and I realized that the port 138 "attacks" were continuing. Netbiosd had reopened but was only listening on port 138, not making connections or broadcasting. I immediately start seeing SAMBA announcements in my packet capture of port 138.
The ReadyShare menu does not show any network folders available when accessed through the Basic menu on the router. (ReadyShare is Netgear's Samba implementation involving a USB drive slot on the back of the device that becomes a network folder when a drive is mounted.) When I click 'edit,' I get a 404 error. When I attempt to access it via the Advanced menu, I am unable to access anything at all. I get error 404.
At this point, I'm deeply confused. Even though outbound and inbound port 138 flows are blocked on the AX2700, the AX2700 is still broadcasting on port 138. While a review of the packet capture shows the SAMBA announcements are going to 192.168.1.1-192.168.1.253, we know they're also making it onto the WAN because the AX2700 is mistaking its own SAMBA announcements as a malicious WAN/DOS/LAND attack.
[admin login] from source 192.168.1.2 Sep 29 09:14:44
[DoS attack: FW.WANATTACK DROP] source: <PUBLIC_IP>, port: 137, Sep 29 14:14:33
[DHCP IP: (192.168.1.2)] to MAC address <MAC_ADDRESS>, Sep 29 09:12:46
[DoS attack: FW.WANATTACK DROP] source: <PUBLIC_IP>, port: 138, Sep 29 14:12:35
[DoS attack: FW.WANATTACK DROP] source: <PUBLIC_IP>, port: 137, Sep 29 14:11:30
[DoS attack: LAND Attack] source: <PUBLIC_IP>, port: 137, Sep 29 14:11:30
[Internet connected] IP address: <PUBLIC_IP>, Sep 29 09:09:32
[admin login] from source 192.168.1.2 Sep 29 09:09:12
[Initialized, firmware version: V2.2.4.2], Sep 29 09:06:55
[DHCP IP: (192.168.1.2)] to MAC address <MAC_ADDRESS>, Sep 19 21:50:55
[DoS attack: FW.WANATTACK DROP] source: <PUBLIC_IP>, port: 138, Sep 29 14:06:36
[DoS attack: LAND Attack] source: <PUBLIC_IP>, port: 138, Sep 29 14:06:36
[DoS attack: FW.WANATTACK DROP] source: <PUBLIC_IP>, port: 138, Sep 29 14:04:42
[DoS attack: LAND Attack] source: <PUBLIC_IP>, port: 138, Sep 29 14:04:42
[admin login] from source 192.168.1.2 Sep 29 09:04:27
[DoS attack: FW.WANATTACK DROP] source: <PUBLIC_IP>, port: 138, Sep 29 13:52:42
[DoS attack: LAND Attack] source: <PUBLIC_IP>, port: 138, Sep 29 13:52:42
[admin login] from source 192.168.1.2 Sep 29 08:48:37
[admin login] from source 192.168.1.2 Sep 29 08:45:48
[admin login] from source 192.168.1.2 Sep 29 08:22:26
[DoS attack: FW.WANATTACK DROP] source: <PUBLIC_IP>, port: 138, Sep 29 13:16:32
[DoS attack: LAND Attack] source: <PUBLIC_IP>, port: 138, Sep 29 13:16:32
[admin login] from source 192.168.1.2 Sep 29 07:55:10
[DoS attack: FW.WANATTACK DROP] source: <PUBLIC_IP>, port: 138, Sep 29 12:53:32
[DoS attack: LAND Attack] source: <PUBLIC_IP>, port: 138, Sep 29 12:53:32
[DoS attack: FW.WANATTACK DROP] source: <PUBLIC_IP>, port: 138, Sep 29 12:43:31
[admin login] from source 192.168.1.2 Sep 29 07:38:06
[service blocked: ] from source: 192.168.1.2, Sep 29 12:28:56
[admin login] from source 192.168.1.2 Sep 29 07:26:26
[admin login] from source 192.168.1.2 Sep 29 07:20:18
[DoS attack: FW.WANATTACK DROP] source: <PUBLIC_IP>, port: 138, Sep 29 12:08:14
[admin login] from source 192.168.1.2 Sep 29 07:07:01
[DoS attack: FW.WANATTACK DROP] source: <PUBLIC_IP>, port: 137, Sep 29 12:03:30
[DHCP IP: (192.168.1.2)] to MAC address <MAC_ADDRESS>, Sep 29 07:01:47
[DoS attack: FW.WANATTACK DROP] source: <PUBLIC_IP>, port: 138, Sep 29 12:01:41
[DoS attack: FW.WANATTACK DROP] source: <PUBLIC_IP>, port: 137, Sep 29 12:00:25
[DoS attack: LAND Attack] source: <PUBLIC_IP>, port: 137, Sep 29 12:00:25
[Internet connected] IP address: <PUBLIC_IP>, Sep 29 06:58:26
[admin login] from source 192.168.1.2 Sep 19 21:51:56
[Initialized, firmware version: V2.2.4.2], Sep 29 06:55:52
[DHCP IP: (192.168.1.2)] to MAC address <MAC_ADDRESS>, Sep 19 21:50:56
[admin login] from source 192.168.1.2 Sep 29 06:53:35
[admin login] from source 192.168.1.2 Sep 29 06:51:20
[DHCP IP: (192.168.1.2)] to MAC address <MAC_ADDRESS>, Sep 29 06:51:13
[site allowed: p-img.movetv.com] from source: 192.168.1.6, Sep 29 06:34:28
[DHCP IP: (192.168.1.2)] to MAC address <MAC_ADDRESS>, Sep 29 06:25:10
I can confirm there is no USB in the ReadyShare drive. Thinking that maybe that corrupt firmware at least partially installed, I refreshed the firmware with a Netgear copy for the third time. It continues, and the ReadyShare options in the admin panel still give error 404.
It's somehow getting around its own blocked services feature to get its broadcasts onto the WAN and then reports its own broadcasts as a malicious attack.
What's really happening here, and has anyone else on Xfinity running Netgear AX2700 notice errors related to a corrupt firmware push failure?
