My firewall is logging some very odd (to me at least) connection attempts that appear to originate from the Airport Extreme that is our Internet gateway.
Here are some sample log entries from the firewall (Mac Mini running 10.6.8):
Jul 16 22:25:55 cabrini ipfw: 65534 Deny TCP 220.127.116.11:47677 10.0.1.2:5222 in via en0
Jul 16 22:26:12 cabrini ipfw: 65534 Deny TCP 18.104.22.168:42704 10.0.1.2:8008 in via en0
22.214.171.124 is the WAN interface address of the Airport Extreme (802.11n, 2nd generation), 10.0.1.2 is the Ethernet interface on the Mac Mini. Port 5222 is used by Jabber, 8008 is used as an alternate HTTP port. Neither makes any sense to me as "normal" traffic coming from the base station.
Does anybody have any idea what might be going on here?
MacBook Pro (15-inch 2.4/2.2 GHz), Mac OS X (10.7.4)