mybe some Adware talking to there home servers. I guess the only thing you can do to get sure, is making a tcpdump the next time the alerts are triggerd.
Here to. I get the E-Mail that the port scan is detected and source and target is the same IP from the WAN Interface. This just started about a month 20 days ago. I'f had the firewall up for almost a year and have never seen them before