I have recently installed astaro and have seen a lot of traffic dropped on UDP ports 1026-1027. Not enough it seems to set of IPS but still enough for me to take notice when I searched the logs history.
What I'm having trouble with is this..
The source MAC is always the same and the source IP is always different.
The only conclusion I can come up with is that this is a spoofed MAC and the person on the other end is running TOR to conceal their true source IP.
Does that sound about right? Or am I way off base?
Included is a portion of the PF log filtered to show all traffic on UDP 1026.
This thread was automatically locked due to age.