Asus router phones home when booted


Just an FYI.
I have been watching the boot-up network activity of an Asus AC1900P running the latest firmware,

For whatever reason, it makes a STUN call to Google to learn its public IP address. I see this as a UDP request to port 19302 at

This is followed by 5 outbound requests all to Asus.

Two requests are made They are TCP requests on port 443 to
One request is made to It was TCP on port 443 to
Two requests are made to Again, TCP to port 443 at

None of the fancy/advanced options are enabled in the router. Again, this is boot time with no devices connected to the router.


It's checking for firmware updates and signature updates.


Signatures for what? The security software is disabled.
Firmware and Signature updates sound like 2 requests. There were 5 requests in the log.
Do you know if this is documented anywhere? Thank you.


AHS = signature files used by the firmware for built-in security (ASD) and stability (AHS) checks (totally separate from Trend Micro, this is for the router's own built-in security).

STUN check = used to determine the router's real public IP, required for various built-in services for when in a double NAT or CGNAT situation.

dlcdnets = various things. New firmware checks, cloud-based database of DNS servers shown in the dropdown WAN page, OUI database lookups for identifying client devices by MAC address on the networkmap, updated timezone data, and a few more additionnal things.

