Server from US connecting to UK…
After putting in pfSense 2.3.2_P1, I enabled ntopng and noticed weird connections such as below. The machine is a HyperV Windows 2012 R2 Server Host - looks like I will have to rebuild the server! UK Government though?
Looks to be Microsoft related.
You can click the blue infoblock icon in the pfBlockerNG alerts tab to pull up several different Threat source links.
I don't understand how you think rebuilding a server will stop a particular IP address in the UK from attempting to connect to you.
That's why we run firewalls that block unsolicited traffic in the first place.
It's Teredo tunneling. Don't panic, just disable that in the network settings on the Hyper-V server.