Hi Charlie
What exactly in /var/log/messages were you concerned about? I don't see any references to 207.46.x.y.
I was scared because my server was showing root task running 11pm , I could track a lot of connections to 207.46.x.y. AND had a outgoing traffic shapped at total bandwidth for all night!
I discovered they have all different explanations and have learned a lot in process:
I had a lot of outgoing traffic starting at 11pm because my server was attempting to do a backup (using affa for this server). Disabled affa to be 100% sure. Later fixed issues (open files) to allow a quick backup.
I had a lot of connections to M$ because computers were trying to download updates to Windows.
The connections were dying because I had a infected M$ computer on LAN opening thousands of connections to Russia. I disconnected infected computer from LAN!
The dying connections were staying for too long time up/connected because WRT54g had default config (512 connections and timeout = 3600) and getting too busy (95/97% of possible connections open). Change for 1024 connections with timeout=120 (2 min) helped a lot.
When WRT54g was busy and w/high number of connections it started to drop connections... and internet access got unreliable.
oh God... so much thing happened in a few days... and a lot of things happened simultaneously...but it´s all fixed now.
