Hack? External ip coming into VPN, then to Internal IP

My local router logging picked up this:

08-09-2007 01:07:41 Local7.Debug 192.168.1.1 firewall,info HOUSEROUTER–: forward: in:pptp-out1 out:bridge1, proto TCP (SYN), 213.186.44.152:45694->192.168.1.198:2680, len 48


funny thing is though, the interface that this is coming in through, pptp-out1, is a PPTP vpn to a router “B” across the country that is on the 192.168.5.0/24 private network. How would a Outside IP to router B, send a request through the VPN, to a Private IP, and a port that hosts a graphing webserver (this port was not a shot in the dark)…

any ideas? comments

edit: btw, router “B” is mikrotik as well…

there could be some reasons for this;

  • misconfigured port forwarding on router ‘B’.
  • spoofed packets from an internal host on location ‘B’