4
Votes

More detailed logs for ERxxx

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
 
4
Votes

More detailed logs for ERxxx

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
More detailed logs for ERxxx
More detailed logs for ERxxx
2022-03-26 08:07:43 - last edited 2022-03-28 08:47:46
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.0.1

First of all, as a new user of your product: I'm impressed with the out of the box capabilities and features in de Omada SDN Framework. I just migrated my home from Fortinet (where I was employee) to TP-Link. Connectivity in and around my house is really important (as all my lightswitches and electronic equipment can be used over WiFi) and I'm more then impressed by the quality of that part. Also, visibility into the network is really important for me.

However, coming from Fortinet, I lack a bit of the security features. I do understand the ER605 will never be a next-gen firewall (which I didn't use on the FortiGate), but I would like to have some more insights in the alerts. 

 

Example of alerts I get a lot:

"Router detected Large Ping attack and dropped 105 packets."

 

I don't know where to see on which interface this has happened (LAN or WAN). I don't know the source of the attack so I can take measures (if it is internally). I suppose this is just a portscan thingy on the outside of my network, but there is no (or I missed it) way to investigate this issue.

 

Ofcourse, storage is limited on the box, but let's say a 5 day log storage (and otherwise syslog forwarding) would be a good option to consider.

 

 

#1
Options
1 Reply
Re:More detailed logs for ERxxx
2022-03-28 08:14:53
Fully agree with all of your suggestions, I feel exactly the same and the routers do need to step their firewall game up a notch or two with logging etc etc.
#2
Options