Yesterday 2022-07-29 I got 11502 hits in the firewall log from many different IP addresses and countries. All but a couple of them had the same MAC address f4:4b:2a:a5:5f:55. At 9:39 am I got 4600 more and counting.
Just found out that I could block the MAC address. I set it to Reject. The dropped hits were coming in several seconds apart. It’s been over 10 minutes since I added the new rule.
I’m still getting a couple of DROP_CTINVALID hits every 8 minutes since then. Maybe that person will give up soon.