Hoping someone can provide some insight here. I'm running a Verizon Quantum Gateway and have it setup to reject all incoming connections but allow all outgoing connections (default). Until today I was allowing it to respond to ping requests but while looking into this I disabled that functionality.
I always see a handful of connection attempts blocked in my firewall log, and I was told that's fairly normal. What seems abnormal to me is that I seem to have some amount of targeted attempts here. This morning, I have been getting repeated connection attempts from two IP addresses in Poland, every two minutes. Here is a sample from my router's log:
notice<173> Blocked IN=eth0 OUT= MAC=c8:a7:0a:82:bd:c9:2c:21:72:1b:6f:c1:08:00 SRC=212.91.20.90 DST=[myip] LEN=97 TOS=00 PREC=0x00 TTL=56 ID=53869 DF PROTO=TCP SPT=443 DPT=54535 SEQ=143504554 ACK=4209430672 WINDOW=18434 ACK PSH URGP=0 MARK=0
The attempts have been from 212.91.20.90 and 212.91.20.97. Looking back through my logs I can see a few more attempts from similar addresses (212.91.20.92, for example) overnight last night. All are showing as blocked. It's only concerning me since I'm now at 12 attempts over the last half hour from *.90 and *.97.
Is this some type of targeted attack? And is there anything I can do about it?
I always see a handful of connection attempts blocked in my firewall log, and I was told that's fairly normal. What seems abnormal to me is that I seem to have some amount of targeted attempts here. This morning, I have been getting repeated connection attempts from two IP addresses in Poland, every two minutes. Here is a sample from my router's log:
notice<173> Blocked IN=eth0 OUT= MAC=c8:a7:0a:82:bd:c9:2c:21:72:1b:6f:c1:08:00 SRC=212.91.20.90 DST=[myip] LEN=97 TOS=00 PREC=0x00 TTL=56 ID=53869 DF PROTO=TCP SPT=443 DPT=54535 SEQ=143504554 ACK=4209430672 WINDOW=18434 ACK PSH URGP=0 MARK=0
The attempts have been from 212.91.20.90 and 212.91.20.97. Looking back through my logs I can see a few more attempts from similar addresses (212.91.20.92, for example) overnight last night. All are showing as blocked. It's only concerning me since I'm now at 12 attempts over the last half hour from *.90 and *.97.
Is this some type of targeted attack? And is there anything I can do about it?