Wednesday, January 29, 2020

tcp/8090: Confused by Firewall Log Entries

I'm trying to wrap my head around this, I'm looking through my pfSense firewall logs, and I see entries where the source is on a virtual address of a VPN connection.

https://imgur.com/miE7mMr - all of the traffic in question is on tcp/8090.

I run OpenVPN clients on my router, so the source ip is virtual ip addresses of those VPN clients, but what traffic would be attempting to enter my network on those virtual private addresses?

I assume this is not nefarious behavior, I actually suspect it has something to do with OpenVPN checking if the connection is alive or something, but thus far I've been unable to find any information to verify this.



No comments:

Post a Comment