In my logs I discovered regular entries for Port 123/UDP (NTP) from my iPFire IP to a Tor Exit Node. I’ve blocked Tor and I wonder how to find out where these log entries do come from.
I also noticed that the NTP address pools were using addresses in the TOR network.
This shouldn’t be a problem since IPFire can block them, but I still changed the NTP server addresses to avoid them.