Help With Selfhosted Homelab Network Issue
Help With Selfhosted Homelab Network Issue
For the past 3 or so months I've been noticing entries in Suricata that concern me. Maybe they are benign, but figured I'd throw this out there and see if anyone has/is experiencing this.
There is a pattern to these entries. All of them are listed as 'PROTOCOL-ICMP Destination Unreachable Network Unreachable'. But it's like there is a cron that fires this off once every hour and 5 +/- minutes.
These ip ranges are usually from China, Romania, and Singapore. The biggest 'offender' being China:
Thing is, these ip's are usually what I consider 'clean'. Not a lot of abuse reports. On the surface, I know what 'PROTOCOL-ICMP Destination Unreachable Network Unreachable' means. Pretty self explanatory. What I'm trying to figure out is the why part.
I have gone through my logs, monitored for any calls to these ip's from inside the network, and I come up empty. Nothing within my network, whether server or other devices, is requesting data from these ip's. I have no cron set to do such on a hour and 5 minute interval.
So I'm left wondering, is this normal network chatter? Perhaps scraping attempts? Or perhaps breach attempts. So, I sit at the feet of the network experts to be schooled and see if I have something misconfiguration, or if it's nothing to be worried about, or what the devil is going on.
ETA: Suricata is running in conjunction with pFsense as part of a standalone firewall. ETA2: Also running the evil Cloudflare Tunnel/Zero Trust.