Router is getting suspicious packets

ChowdhuryTahrim

Prominent
Jul 17, 2017
4
0
510
I am seeing lot of suspicious network activity middle of the night when nobody is on the computer. AT&T fiber is my network provider
I have following modem
Manufacturer Pace Plc
Model 5268AC
 
IP Address:          45.19.50.103
MAC Address:    e0:22:04:2c:f5:cc
Following is the snipet of firewall logs from the modem.  
 
notice 7/16/2017 22:02 IN=br1 MAC=e0:22:04:2c:f5:cc src=74.82.47.50 DST=45.19.50.103 LEN=40 TTL=240 PROTO=TCP DPT=11211 Drop Unknown Incoming Packet
err 7/16/2017 22:03 IN=br1 MAC=e0:22:04:2c:f5:cc src=5.188.10.251 DST=45.19.50.103 LEN=40 TTL=237 PROTO=TCP DPT=4513 Port Scan
err 7/17/2017 2:52 The previous message was repeated 445 times
warn 7/17/2017 2:52 IN=br1 MAC=e0:22:04:2c:f5:cc src=60.251.253.240 DST=45.19.50.103 LEN=96 TTL=41 PROTO=ICMP ICMP Invalid Type/Code
notice 7/17/2017 2:52 IN=br1 MAC=e0:22:04:2c:f5:cc src=183.83.8.197 DST=45.19.50.103 LEN=40 TTL=45 PROTO=TCP DPT=23 Drop Unknown Incoming Packet
notice 7/17/2017 2:54 IN=br1 MAC=e0:22:04:2c:f5:cc src=180.101.141.6 DST=45.19.50.103 LEN=40 TTL=47 PROTO=TCP DPT=23 Drop Unknown Incoming Packet
notice 7/17/2017 2:54 IN=br1 MAC=e0:22:04:2c:f5:cc src=5.188.10.251 DST=45.19.50.103 LEN=40 TTL=237 PROTO=TCP DPT=4503 Drop Unknown Incoming Packet
notice 7/17/2017 2:55 IN=br1 MAC=e0:22:04:2c:f5:cc src=139.162.79.111 DST=45.19.50.103 LEN=40 TTL=237 PROTO=TCP DPT=8123 Drop Unknown Incoming Packet
err 7/17/2017 2:55 IN=br1 MAC=e0:22:04:2c:f5:cc src=195.154.243.143 DST=45.19.50.103 LEN=437 TTL=51 PROTO=UDP DPT=5060 Port Scan
err 7/17/2017 6:29 The previous message was repeated 290 times
notice 7/17/2017 6:29 IN=br1 MAC=e0:22:04:2c:f5:cc src=141.212.121.193 DST=45.19.50.103 LEN=40 TTL=241 PROTO=TCP DPT=7 echo packet dropped
 
notice 7/17/2017 6:30 IN=br1 MAC=e0:22:04:2c:f5:cc src=80.82.70.26 DST=45.19.50.103 LEN=40 TTL=240 PROTO=TCP DPT=23 Drop Unknown Incoming Packet
notice 7/17/2017 6:31 IN=br1 MAC=e0:22:04:2c:f5:cc src=104.236.183.34 DST=45.19.50.103 LEN=40 TTL=239 PROTO=TCP DPT=22 Drop Unknown Incoming Packet
notice 7/17/2017 6:31 IN=br1 MAC=e0:22:04:2c:f5:cc src=91.211.3.106 DST=45.19.50.103 LEN=40 TTL=240 PROTO=TCP DPT=43389 Drop Unknown Incoming Packet
notice 7/17/2017 6:33 IN=br1 MAC=e0:22:04:2c:f5:cc src=185.56.82.30 DST=45.19.50.103 LEN=48 TTL=111 PROTO=TCP DPT=5900 Drop Unknown Incoming Packet
err 7/17/2017 6:34 IN=br1 MAC=e0:22:04:2c:f5:cc src=121.29.54.100 DST=45.19.50.103 LEN=40 TTL=239 PROTO=TCP DPT=35469 Port Scan
err 7/17/2017 7:30 The previous message was repeated 57 times
 
Solution
Not a lot but again even if it is what can you possibly do. To do something your router must actually receive the traffic and it has eaten you bandwidth by that time. Your router is doing all that it can by dropping the traffic.

This is one of those things that many times it might be better if the router just dropped the traffic and said nothing. It just stresses some people to see these messages
There is no setting for UPNP for my router. Keep in mind this is taking place 2:52am. There is nobody in the house but me and I am sleeping. Using IP lookup tool, here is what I found

IP Address Host Name Country
195.154.243.143 195-154-243-143.rev.poneytelecom.eu France
41.212.121.193 41.212.121.193.wananchi.com Kenya
74.82.47.50 AT&T services USA
5.188.10.251 5.188.10.251 Croatia (HR)
121.29.54.100 121.29.54.100 China
 
You can pretty much ignore it. You can see your router is dropping all the packets so nothing get past it. This is pretty much normal garbage traffic and scanning that you see on all internet connections. Even if you wanted to there is nothing you can do to prevent it.
 


 
Not a lot but again even if it is what can you possibly do. To do something your router must actually receive the traffic and it has eaten you bandwidth by that time. Your router is doing all that it can by dropping the traffic.

This is one of those things that many times it might be better if the router just dropped the traffic and said nothing. It just stresses some people to see these messages
 
Solution