Bill,
I attempted to look through my records for 138.88.77.89 on my interface and I see quite a
bit of packets from you - so much so that it crashed my NetFlow console upon searching
your IP with a setting of 10,000 flows.
I am receiving encapsulated packets from you, and it seems you've pointed traffic
towards me.
Firewall:
203.87 K 11.09 MB zone_amprwan_dest_DROP all * * 0.0.0.0/0 0.0.0.0/0 - AMPR_DropLoop
Encapsulated:
Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port
Packets Bytes Flows
2020-01-26 10:01:01.733 202.005 IPIP 138.88.77.89:0 -> 141.75.245.225:0
28 8758 1
2020-01-26 10:01:01.733 202.005 IPIP 141.75.245.225:0 -> 138.88.77.89:0
28 2371 1
2020-01-26 10:18:02.902 419.571 IPIP 138.88.77.89:0 -> 90.155.50.1:0
116 9976 1
2020-01-26 10:26:40.783 13495.994 IPIP 176.121.81.53:0 -> 138.88.77.89:0
107 8922 1
de-encapsulated:
Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port
Packets Bytes Flows
2020-01-26 09:18:45.097 88198.195 TCP 138.88.77.89:41958 -> 3.219.211.244:8883
7209 879799 1
2020-01-26 09:18:45.097 88198.195 TCP 3.219.211.244:8883 ->
138.88.77.89:41958 5618 341324 1
2020-01-26 09:31:05.692 86085.778 TCP 138.88.77.89:38410 -> 69.147.82.61:443
8792 2.7 M 1
2020-01-26 09:31:05.692 86085.778 TCP 69.147.82.61:443 ->
138.88.77.89:38410 7968 1.6 M 1
- KB3VWG