Suspicious connection attempts

Recently I’ve noticed multiple connection attempts from an IP address in [a certain country] that’s targeting my Roon Core. I’m curious to know whether anyone else here is seeing something similar? I’m suspicious that perhaps there’s a vulnerability in the platform that’s been discovered.

There are always automated port scans to all external IPs. They are not targeted, simply everything that is externally available will be scanned to see if it’s a potential target in the first place. This in itself means nothing. I suppose you are using ARC.

Yes, I’m running arc. I realize that open ports will be scanned, and that an unprotected system on the internet has only minutes before it’s found and exploited, but I just find it peculiar that I’m seeing frequent repeated attempts on this particular service. Nothing else is getting the same attention. I was curious to know other people’s experience to determine whether there is any wider community knowledge on the topic. I appreciate your input.

Hi, how have you determined this?

I ask as I suspect it’s just that your router is dealing with these port scans and silently bouncing them… but for the open ARC port your internal network monitor is detecting and reporting.