Everything here is smooth sailing. I have been trying to track down a bothersome Suricata entry.
202.136.163.11 PROTOCOL-ICMP destination unreachable port unreachable packet detected
202.136.163.11 PROTOCOL-ICMP destination unreachable port unreachable packet detected
202.136.163.11 PROTOCOL-ICMP destination unreachable port unreachable packet detected
202.136.163.11 PROTOCOL-ICMP destination unreachable port unreachable packet detected
ad nauseum. There are three individual ips. One from Singapore, one from China and one from Romania. They are being blocked, so that's good. Thing is, these are from realitvly 'clean' sources:
120.132.37.195 was not found in our database
202.136.163.11 was found in our database! This IP was reported 5 times. Confidence of Abuse is 0%:
On the server side, I have nothing calling out to these ip. That's what was really bugging me. Nothing server side, just these three bothersome ip hammering Suricata. Generally, I would dismiss as benign and part of normal UDP behavior. However, it's the constant hammering that makes me suspicious. Could be high volume port scanning. However, it could also be known attack campaigns like UDP amplification attempts.
Other than that, I might find something to get into today.