Internal device discovery triggers gateway alerts and dropped packets

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Internal device discovery triggers gateway alerts and dropped packets

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Internal device discovery triggers gateway alerts and dropped packets
Internal device discovery triggers gateway alerts and dropped packets
2022-07-12 00:38:43
Model: ER605 (TL-R605)  
Hardware Version: V1
Firmware Version: 1.2.1

I have a process on the LAN which does device discovery on a schedule.  It isn't doing an intrusive port scan but it uses pings to identify the devices.

 

Whenever this is run, it triggers an event that reads "ER605 Gateway detected Large Ping attack and dropped 134 packets.".  I haven't yet found a way to whitelist this traffic.

 

However, it seems strange that the gateway would detect that from the LAN and drop packets by default.

 

Is there any way to stop this from happening or whitelist the LAN to allow ping scans? 

  0      
  0      
#1
Options
2 Reply
Re:Internal device discovery triggers gateway alerts and dropped packets
2022-07-13 07:30:40

Dear @Alex789 ,

 

Alex789 wrote

I have a process on the LAN which does device discovery on a schedule.  It isn't doing an intrusive port scan but it uses pings to identify the devices.

Whenever this is run, it triggers an event that reads "ER605 Gateway detected Large Ping attack and dropped 134 packets.".  I haven't yet found a way to whitelist this traffic.

However, it seems strange that the gateway would detect that from the LAN and drop packets by default.

Is there any way to stop this from happening or whitelist the LAN to allow ping scans? 

 

The detection mechanism of this router is such that the relevant alert is given only when packets exceeding 1024 bytes are detected.
We suggest that you try changing the settings on this Device Discovery program to see if you can change the Ping bytes to be smaller.

 

Best Regards!
 

Best Regards! >> Omada EAP Firmware Trial Available Here << >> Get the Latest Omada SDN Controller Releases Here << *Try filtering posts on each forum by Label of [Early Access]*
  0  
  0  
#2
Options
Re:Internal device discovery triggers gateway alerts and dropped packets
2022-07-13 14:22:43

  @Hank21 It doesn't have any ability to change that.  Is there no way to whitelist anything from being blocked?

  0  
  0  
#3
Options