My MikroTik is Hacked!!! Found file 7wmp0b4s.rsc

99.999% of these attacks are machine scan, so if they test one port, the possibility are large for that they tries more ports later and since I do have some port open, its better to block them so my open port will not be attacked.

OK, if you put it this way, then no, I don’t see much value in using it. Most malware will attack public addresses anyway. Out of curiosity, you may add it an let it log, to see whether some stupid malware is running in your LAN.

Ahh okay, i see a log, to know if… that makes sense.
Then the follow is also valid,
Detect, then block lanip.
Then find out who is pissed off that their internet doesnt work anymore.
I like it!!!

Or you can keep the IPSec open but add QoS and give then a very slow connection, like 1kbps.
Also logg all their traffic and see where they go.
You can also redirect port 80/443 to a specific web server, so same web page opens all the time.