I'm a novice Mikrotik user. Device model
CCR1036-12G-4S.
I see "pptp, info - TCP connection established from" records in the logs. I don't know who these ip addresses are.

Is this a security hole? If so how can I turn this off?
Thank you.
That would be too complex for most retail users to accomplish. Best is keep ROS updated, maintain the firewall filters, should give a safer environment.I have a /16 network on internet and it gets a constant flow of 1-2 Mbit/s of this crap.
I run some automatic blacklisting on that network (which is not as straightforward as you would think), and it lists 70000-80000 systems doing such scans all the time.
I agree, there are quite a number of pitfalls with that. I would not recommend to setup an automatic blacklist filter unless all the implications are known and workarounds for known problems are included.That would be too complex for most retail users to accomplish. Best is keep ROS updated, maintain the firewall filters, should give a safer environment.I have a /16 network on internet and it gets a constant flow of 1-2 Mbit/s of this crap.
I run some automatic blacklisting on that network (which is not as straightforward as you would think), and it lists 70000-80000 systems doing such scans all the time.