Cloud Gateway Ultra, up to date. I received three IDS threats to two iPhones and a Samsung TV in succession. IDS blocked the intrusions, all from the same IP and I added it to the IPS Deny list. In the week after the attempted intrusions, the two iPhones and TV repeatedly (a dozen or so times in a day) try to connect to the source IP address of the intrusions. It's a site that AbuseIPDB rates bad, including multiple recent attacks.
I've rebooted the UCGU to flush the DNS cache with no change. I'm puzzled how the blocked intrusions could have affected the iPhones or TV and why they would be repeatedly trying to connect to the blocked IP. I'd appreciate any guidance. Thanks!
Source: r/Ubiquiti · by /u/OldGrumpyAndRetired