I found not the right config for (two) firewall rule and hope someone can help me.
The firewall log file is full of this drop info. The drop is ok but I will not that this Info is in the log file.
AVM says:
: TCP port 53805 (or other port between 50001 and 59999):
The FRITZ! Box regularly uses TCP port 53805 or another randomly selected port between 50001 and 59999 to determine whether there are other Mesh-compatible FRITZ! Box models, FRITZ! Repeaters or FRITZ! Powerline adapters in the home network. The devices found are displayed in the FRITZ! Box user interface under “Home Network> Mesh”.
Go to firewall/firewall groups, click on “services”. Give a name to the new service (e.g. fritzbox scanning). Introduce the range of ports “50001-59999”.
Now that you have the port range, go to /firewall rules and create a new rule:
Source: fritzbox IP
Destination: your local network (e.g. 192.168.2.1/24)
protocol: preset
services: fritzbox scanning <— the name you have chosen in “services”
This is helpful for:
###############
Source: Source address (MAC/IP address or network): Mac address
Destination: Standard networks: Any
Protocol
Preset - → Services <fritzbox scanning | see above cfusco (ports “50001-59999”)>
Reject
###############
No more firewall log entries for port example: 53805