Interesting blocklist traffic

I just started using a new IP Blocklist and while reviewing Firewall log (blocklist), I found very interesting traffic involving Protocol 47

Just for information

It is possible that the attacker is attempting to exploit vulnerabilities in the GRE protocol.

e.g.

Regards

1 Like

What would be the reason behind an attack using Protocol 47 ?

There is not even a destination port recorded.

GRE doesn’t use ports.

https://david-waiting.medium.com/a-beginners-guide-to-generic-routing-encapsulation-fb2b4fb63abb