CCR-firewall suspicious established connections

I don’t like seeing these random connections in the firewall. Nothing in blue is expected traffic. We have no incoming traffic rules (from the internet) other than IPsec.

Ruleset:

Any ideas why these are being established and/or how I might stop them?

thanks