Bill,
I attempted to look through my records for 138.88.77.89 on my interface and I see quite a
bit of packets from you - so much so that it crashed my NetFlow console upon searching
your IP with a setting of 10,000 flows.
I am receiving encapsulated packets from you, and it seems you've pointed traffic
towards me.
Firewall:
203.87 K 11.09 MB zone_amprwan_dest_DROP all * * 0.0.0.0/0 0.0.0.0/0 - AMPR_DropLoop
Encapsulated:
Date first seen          Duration Proto      Src IP Addr:Port          Dst IP Addr:Port
Packets    Bytes Flows
2020-01-26 10:01:01.733   202.005 IPIP      138.88.77.89:0     ->   141.75.245.225:0
28     8758     1
2020-01-26 10:01:01.733   202.005 IPIP    141.75.245.225:0     ->     138.88.77.89:0
28     2371     1
2020-01-26 10:18:02.902   419.571 IPIP      138.88.77.89:0     ->      90.155.50.1:0
116     9976     1
2020-01-26 10:26:40.783 13495.994 IPIP     176.121.81.53:0     ->     138.88.77.89:0
107     8922     1
de-encapsulated:
Date first seen          Duration Proto      Src IP Addr:Port          Dst IP Addr:Port
Packets    Bytes Flows
2020-01-26 09:18:45.097 88198.195 TCP       138.88.77.89:41958 ->    3.219.211.244:8883
7209   879799     1
2020-01-26 09:18:45.097 88198.195 TCP      3.219.211.244:8883  ->
138.88.77.89:41958     5618   341324     1
2020-01-26 09:31:05.692 86085.778 TCP       138.88.77.89:38410 ->     69.147.82.61:443
8792    2.7 M     1
2020-01-26 09:31:05.692 86085.778 TCP       69.147.82.61:443   ->
138.88.77.89:38410     7968    1.6 M     1
- KB3VWG