(click pic to enlarge) My snort log shows a couple of entries like: Proto Class Source Port Destination Port SID UDP | Misc Attack | 188.165.213.456 | 6681 | 10.4.6.169 | 37417 | 1:2522521 Description ET TOR Known Tor Relay/Router (Not Exit) Node UDP Traffic group 261 In other words someone attacks me out of TOR trough the VPN connection? Is the airserver compromised? How can the attacker know my internal VPN IP (10.4.6.169)? It seems he attacks from inside the tunnel... Should I be concerned? Thanks for your thoughts! regards