LOG ?

From time to time I see in log these errors or informations:
received ISAKMP from 212.114.235.7:500 , phase 1 Indentity protection
received ISAKMP from 212.114.235.7:500 , phase 2 Informational

It seems that in this time my internet conection is little slower .
What this mean ?
Is this some kind of atack?

This is a host attempting to negotiate an IPSEC connection.

Block incoming access to all ports that you’re not actively using.

Regards

Andrew

I already have hotspot setup … and all firewall rules …
Does it will be ok if I put rule like this on the botom?:

ip firewall rule input add in-interface=all action=drop comment="Log and drop everything else"