Unknown IPs in log

These are international IPs unknown to me. I am assuming these have nothing to do with the service and I should block them or are they possibly outbound.

2021/02/22 06:36:37.669204 [NAT] Successfully mapped port 8089 using natpmp 2021/02/22 07:36:37.720337 [NAT] Successfully mapped port 8089 using natpmp 2021/02/22 08:04:57.267517 http: TLS handshake error from **150.109.182.32:55968**: remote error: tls: bad certificate 2021/02/22 08:36:37.769999 [NAT] Successfully mapped port 8089 using natpmp 2021/02/22 09:36:37.812362 [NAT] Successfully mapped port 8089 using natpmp 2021/02/22 10:00:27.311740 http: TLS handshake error from **37.49.230.23:60013**: tls: client offered only unsupported versions: [301] 2021/02/22 10:19:08.232690 http: TLS handshake error from **37.49.230.23:51451**: tls: client offered only unsupported versions: [301] 2021/02/22 10:36:37.814295 [NAT] Successfully mapped port 8089 using natpmp

Most likely.
Anyone that opens up a port to the Internet can expect it to be scanned and probed.

How do I know if its not a service that is being accessed via a M3U or TVE
One IP is supposedly in Thailand the other in Netherlands. Neither location ring a bell as far as registered services

Because it is an outside computer trying to connect to your server. When you access internet streams, your computer is the one contacting the other servers. TVE streams and the like do not initiate the inbound traffic.

(As an analogy, that's like saying, "When my phone rings, how do I know that it's not my phone that initiated the call?")

1 Like

Ok thats what I wanted to check that it was inbound. Ok will blacklist them. Thanks guys

1 Like