We have twice in the past week seen this traffic that appears to be coming from outside our network at first glance to one of our DSL customers.
9 IP-188.8.131.52 IP-172.16.7.248 64 19:04:26.199174 HTTPS Src= 443,Dst= 2198
10 IP-184.108.40.206 IP-172.16.7.248 64 19:04:26.214186 HTTPS Src= 443,Dst= 2198
11 IP-220.127.116.11 IP-172.16.7.248 64 19:04:26.244356 HTTPS Src= 443,Dst= 2198
12 IP-18.104.22.168 IP-172.16.7.248 64 19:04:26.256164 HTTPS Src= 443,Dst= 2198
13 IP-22.214.171.124 IP-172.16.7.248 64 19:04:26.268733 HTTPS Src= 443,Dst= 2198
While this traffic is present other customers on this network can no longer access the Internet nor can they renew or receive an IP address from our dhcp server.
The 66 address resolves to marketscore.com. Anyone seen this before? One item that comes to mind is that I placed a ACL in our edge router to block all traffic from this particular address with no results. That makes me think the traffic may not have been actually coming from outside. It's currently not happening but if it does again I'll be better able to identify if it in in fact coming from outside.