Coggy wrote: ⤴Fri Apr 29, 2022 5:34 am
I
assume that the stuff being blocked is all incoming.
I can see two things trying to happen that are being blocked:
Firstly, UDP packets from port 1900 to assorted high ports. ...
Secondly, I see incoming connections to TCP port 3389 which is Remote Desktop Protocol. ...
That log was taken from your mother's PC, wasn't it?
Hi Coggy, Thanks for your thoughts and suggestions. (Sorry I'm a bit slow replying due to pandemic-related staff shortages and work.) Here is a log from today with SRC and DST:
Code: Select all
Jul 3 10:54:36 VBox-R kernel: [ 1550.545872] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=13261 PROTO=UDP SPT=1900 DPT=33197 LEN=441
Jul 3 10:54:40 VBox-R kernel: [ 1554.433509] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=14802 PROTO=UDP SPT=1900 DPT=54400 LEN=441
Jul 3 10:54:42 VBox-R kernel: [ 1556.448956] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=15496 PROTO=UDP SPT=1900 DPT=38296 LEN=441
Jul 3 10:54:44 VBox-R kernel: [ 1558.518850] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=16697 PROTO=UDP SPT=1900 DPT=53133 LEN=441
Jul 3 10:54:46 VBox-R kernel: [ 1560.528031] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=18197 PROTO=UDP SPT=1900 DPT=51508 LEN=441
Jul 3 10:54:48 VBox-R kernel: [ 1562.549139] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=18600 PROTO=UDP SPT=1900 DPT=58228 LEN=441
Jul 3 10:58:42 VBox-R kernel: [ 1796.549969] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=27388 PROTO=UDP SPT=1900 DPT=38152 LEN=441
Jul 3 10:58:47 VBox-R kernel: [ 1801.596058] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=32346 PROTO=UDP SPT=1900 DPT=40482 LEN=441
Jul 3 10:58:49 VBox-R kernel: [ 1803.603013] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=33237 PROTO=UDP SPT=1900 DPT=35395 LEN=441
Jul 3 10:59:14 VBox-R kernel: [ 1828.494328] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=53083 PROTO=UDP SPT=1900 DPT=49828 LEN=441
Jul 3 10:59:16 VBox-R kernel: [ 1830.501608] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=54736 PROTO=UDP SPT=1900 DPT=47153 LEN=441
Jul 3 10:59:18 VBox-R kernel: [ 1832.505640] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=55940 PROTO=UDP SPT=1900 DPT=40415 LEN=441
Jul 3 11:03:50 VBox-R kernel: [ 2104.008056] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=90 TOS=0x00 PREC=0x00 TTL=64 ID=13060 PROTO=UDP SPT=137 DPT=42192 LEN=70
Jul 3 11:03:53 VBox-R kernel: [ 2107.018635] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=90 TOS=0x00 PREC=0x00 TTL=64 ID=14430 PROTO=UDP SPT=137 DPT=38068 LEN=70
Jul 3 11:08:21 VBox-R kernel: [ 2375.045720] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=44217 PROTO=UDP SPT=1900 DPT=42393 LEN=441
Jul 3 11:17:23 VBox-R kernel: [ 2917.569268] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=43761 PROTO=UDP SPT=1900 DPT=36001 LEN=441
Jul 3 11:19:07 VBox-R kernel: [ 3021.775931] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=97.74.81.123 DST=192.168.1.70 LEN=40 TOS=0x00 PREC=0x00 TTL=237 ID=28107 PROTO=TCP SPT=40206 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0
Jul 3 11:19:16 VBox-R kernel: [ 3030.195113] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=37.9.13.178 DST=192.168.1.70 LEN=40 TOS=0x00 PREC=0x20 TTL=240 ID=23407 PROTO=TCP SPT=38237 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0
Jul 3 11:20:35 VBox-R kernel: [ 3109.770193] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=30088 PROTO=UDP SPT=1900 DPT=52726 LEN=441
Jul 3 11:20:39 VBox-R kernel: [ 3113.551607] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=31813 PROTO=UDP SPT=1900 DPT=60780 LEN=441
Jul 3 11:20:41 VBox-R kernel: [ 3115.557974] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=32576 PROTO=UDP SPT=1900 DPT=54837 LEN=441
Jul 3 11:27:49 VBox-R kernel: [ 3542.966499] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=10609 PROTO=UDP SPT=1900 DPT=53542 LEN=441
Jul 3 11:27:52 VBox-R kernel: [ 3546.857563] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=11349 PROTO=UDP SPT=1900 DPT=48173 LEN=441
Jul 3 11:27:54 VBox-R kernel: [ 3548.863953] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=13013 PROTO=UDP SPT=1900 DPT=46127 LEN=441
Jul 3 11:28:47 VBox-R kernel: [ 6.194977] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=53273 PROTO=UDP SPT=1900 DPT=36478 LEN=441
Jul 3 11:28:49 VBox-R kernel: [ 8.203751] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=55010 PROTO=UDP SPT=1900 DPT=49519 LEN=441
Jul 3 11:29:32 VBox-R kernel: [ 7.623815] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=11251 PROTO=UDP SPT=1900 DPT=60455 LEN=441
Jul 3 11:29:34 VBox-R kernel: [ 9.439500] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=104.16.160.101 DST=192.168.1.70 LEN=1228 TOS=0x00 PREC=0x00 TTL=59 ID=4536 DF PROTO=UDP SPT=443 DPT=53612 LEN=1208
Jul 3 11:29:34 VBox-R kernel: [ 9.439595] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=104.16.160.101 DST=192.168.1.70 LEN=1228 TOS=0x00 PREC=0x00 TTL=59 ID=4537 DF PROTO=UDP SPT=443 DPT=53612 LEN=1208
Jul 3 11:29:34 VBox-R kernel: [ 9.645783] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=13145 PROTO=UDP SPT=1900 DPT=51220 LEN=441
Jul 3 11:33:24 VBox-R kernel: [ 240.836286] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=198.235.24.14 DST=192.168.1.70 LEN=44 TOS=0x00 PREC=0x00 TTL=248 ID=54321 PROTO=TCP SPT=62362 DPT=3389 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 3 11:34:45 VBox-R kernel: [ 321.776056] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=24020 PROTO=UDP SPT=1900 DPT=54547 LEN=441
Jul 3 11:34:49 VBox-R kernel: [ 325.620748] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=24415 PROTO=UDP SPT=1900 DPT=36431 LEN=441
Jul 3 11:34:51 VBox-R kernel: [ 327.628151] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=25745 PROTO=UDP SPT=1900 DPT=44505 LEN=441
Jul 3 11:42:30 VBox-R kernel: [ 786.656219] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=53304 PROTO=UDP SPT=1900 DPT=34378 LEN=441
Jul 3 11:42:34 VBox-R kernel: [ 790.429013] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=56873 PROTO=UDP SPT=1900 DPT=42933 LEN=441
Jul 3 11:42:36 VBox-R kernel: [ 792.440406] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=57913 PROTO=UDP SPT=1900 DPT=59845 LEN=441
Jul 3 11:42:53 VBox-R kernel: [ 810.069515] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=103.207.38.164 DST=192.168.1.70 LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=32005 PROTO=TCP SPT=51276 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0
Jul 3 11:45:45 VBox-R kernel: [ 981.653160] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=90 TOS=0x00 PREC=0x00 TTL=64 ID=30321 PROTO=UDP SPT=137 DPT=53230 LEN=70
Jul 3 11:45:48 VBox-R kernel: [ 984.689058] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=90 TOS=0x00 PREC=0x00 TTL=64 ID=30645 PROTO=UDP SPT=137 DPT=40968 LEN=70
Jul 3 11:48:27 VBox-R kernel: [ 1144.085892] [UFW BLOCK] IN=enp0s3 OUT= MAC=YYYY SRC=192.168.1.200 DST=224.0.0.251 LEN=32 TOS=0x00 PREC=0x00 TTL=1 ID=18958 PROTO=2
Jul 3 11:48:27 VBox-R kernel: [ 1144.086674] [UFW BLOCK] IN=enp0s3 OUT= MAC=YYYY SRC=192.168.1.200 DST=224.0.0.251 LEN=32 TOS=0x00 PREC=0x00 TTL=1 ID=60845 PROTO=2
Jul 3 11:50:20 VBox-R kernel: [ 7.852496] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=10607 PROTO=UDP SPT=1900 DPT=50995 LEN=441
Jul 3 11:50:22 VBox-R kernel: [ 9.861701] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=11151 PROTO=UDP SPT=1900 DPT=57040 LEN=441
Jul 3 11:59:22 VBox-R kernel: [ 550.269315] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=11013 PROTO=UDP SPT=1900 DPT=49053 LEN=441
Jul 3 12:08:22 VBox-R kernel: [ 1090.768099] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=36962 PROTO=UDP SPT=1900 DPT=59325 LEN=441
Jul 3 12:16:30 VBox-R kernel: [ 8.642612] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=36363 PROTO=UDP SPT=1900 DPT=35357 LEN=441
Jul 3 12:16:32 VBox-R kernel: [ 10.700152] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=461 TOS=0x00 PREC=0x00 TTL=64 ID=36486 PROTO=UDP SPT=1900 DPT=59995 LEN=441
Jul 3 12:17:01 VBox-R kernel: [ 39.347428] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=72.167.39.40 DST=192.168.1.70 LEN=40 TOS=0x00 PREC=0x00 TTL=235 ID=52646 PROTO=TCP SPT=58839 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0
1. The UDP packets to port 1900 are all from 192.168.1.254, which is my router. My guess is that the calls to port 1900 are the router using the Simple Service Discovery Protocol for UPnP e.g. refer
https://en.wikipedia.org/wiki/Simple_Se ... y_Protocol. (192.168.1.70 is the Nomachine server, which is a Virtualbox running LM191 as guest.)
Here is the same log but with all lines containing SPT=1900 filtered out i.e. removed. Does this help identify ana issue regarding access to Nomachine through ufw somehow?
Code: Select all
Jul 3 11:03:50 VBox-R kernel: [ 2104.008056] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=90 TOS=0x00 PREC=0x00 TTL=64 ID=13060 PROTO=UDP SPT=137 DPT=42192 LEN=70
Jul 3 11:03:53 VBox-R kernel: [ 2107.018635] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=90 TOS=0x00 PREC=0x00 TTL=64 ID=14430 PROTO=UDP SPT=137 DPT=38068 LEN=70
Jul 3 11:19:07 VBox-R kernel: [ 3021.775931] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=97.74.81.123 DST=192.168.1.70 LEN=40 TOS=0x00 PREC=0x00 TTL=237 ID=28107 PROTO=TCP SPT=40206 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0
Jul 3 11:19:16 VBox-R kernel: [ 3030.195113] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=37.9.13.178 DST=192.168.1.70 LEN=40 TOS=0x00 PREC=0x20 TTL=240 ID=23407 PROTO=TCP SPT=38237 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0
Jul 3 11:29:34 VBox-R kernel: [ 9.439500] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=104.16.160.101 DST=192.168.1.70 LEN=1228 TOS=0x00 PREC=0x00 TTL=59 ID=4536 DF PROTO=UDP SPT=443 DPT=53612 LEN=1208
Jul 3 11:29:34 VBox-R kernel: [ 9.439595] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=104.16.160.101 DST=192.168.1.70 LEN=1228 TOS=0x00 PREC=0x00 TTL=59 ID=4537 DF PROTO=UDP SPT=443 DPT=53612 LEN=1208
Jul 3 11:33:24 VBox-R kernel: [ 240.836286] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=198.235.24.14 DST=192.168.1.70 LEN=44 TOS=0x00 PREC=0x00 TTL=248 ID=54321 PROTO=TCP SPT=62362 DPT=3389 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 3 11:42:53 VBox-R kernel: [ 810.069515] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=103.207.38.164 DST=192.168.1.70 LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=32005 PROTO=TCP SPT=51276 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0
Jul 3 11:45:45 VBox-R kernel: [ 981.653160] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=90 TOS=0x00 PREC=0x00 TTL=64 ID=30321 PROTO=UDP SPT=137 DPT=53230 LEN=70
Jul 3 11:45:48 VBox-R kernel: [ 984.689058] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=192.168.1.254 DST=192.168.1.70 LEN=90 TOS=0x00 PREC=0x00 TTL=64 ID=30645 PROTO=UDP SPT=137 DPT=40968 LEN=70
Jul 3 11:48:27 VBox-R kernel: [ 1144.085892] [UFW BLOCK] IN=enp0s3 OUT= MAC=YYYY SRC=192.168.1.200 DST=224.0.0.251 LEN=32 TOS=0x00 PREC=0x00 TTL=1 ID=18958 PROTO=2
Jul 3 11:48:27 VBox-R kernel: [ 1144.086674] [UFW BLOCK] IN=enp0s3 OUT= MAC=YYYY SRC=192.168.1.200 DST=224.0.0.251 LEN=32 TOS=0x00 PREC=0x00 TTL=1 ID=60845 PROTO=2
Jul 3 12:17:01 VBox-R kernel: [ 39.347428] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=72.167.39.40 DST=192.168.1.70 LEN=40 TOS=0x00 PREC=0x00 TTL=235 ID=52646 PROTO=TCP SPT=58839 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0
(PS. I tried whitelisting the client machine trying to access the Nomachine Server but this didn't help.)
2. I had thought that those TCP connections to port 3389 were a red herring because I had been using the same virtual machine to trial access using RDP (which I was able to get working). However, attempts to port 3389 are still occurring as shown in the log but filtered to remove lines containing DPT=3389, as seen next. Although the MAC address is the same, interestingly the SRC (=Source IP addresses?) are not even local (with 1 exception). Is it possible that these are from a DDNS service, which I have also been looking at?
Code: Select all
Jul 3 11:19:07 VBox-R kernel: [ 3021.775931] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=97.74.81.123 DST=192.168.1.70 LEN=40 TOS=0x00 PREC=0x00 TTL=237 ID=28107 PROTO=TCP SPT=40206 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0
Jul 3 11:19:16 VBox-R kernel: [ 3030.195113] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=37.9.13.178 DST=192.168.1.70 LEN=40 TOS=0x00 PREC=0x20 TTL=240 ID=23407 PROTO=TCP SPT=38237 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0
Jul 3 11:33:24 VBox-R kernel: [ 240.836286] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=198.235.24.14 DST=192.168.1.70 LEN=44 TOS=0x00 PREC=0x00 TTL=248 ID=54321 PROTO=TCP SPT=62362 DPT=3389 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 3 11:42:53 VBox-R kernel: [ 810.069515] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=103.207.38.164 DST=192.168.1.70 LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=32005 PROTO=TCP SPT=51276 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0
Jul 3 12:17:01 VBox-R kernel: [ 39.347428] [UFW BLOCK] IN=enp0s3 OUT= MAC=XXXX SRC=72.167.39.40 DST=192.168.1.70 LEN=40 TOS=0x00 PREC=0x00 TTL=235 ID=52646 PROTO=TCP SPT=58839 DPT=3389 WINDOW=10