Noted the following firewall events in my log:
04:47:05, 10 Jun. IN: ACCEPT [57] Connection closed (Port Forwarding: TCP [192.168.1.65]:4006 <--> [143.159.XXX.XX]:57616 - - - [193.27.228.161]:55235 CLOSED/SYN_SENT ppp3 NAPT)
04:45:04, 10 Jun. IN: ACCEPT [54] Connection opened (Port Forwarding: TCP [192.168.1.65]:4006 <--> [143.159.XXX.XX]:57616 - - - [193.27.228.161]:55235 CLOSED/SYN_SENT ppp3 NAPT)
14:28:45, 08 Jun. IN: ACCEPT [57] Connection closed (Port Forwarding: TCP [192.168.1.65]:4006 <--> [143.159.XXX.XX]:55299 - - - [185.176.27.178]:40210 CLOSED/SYN_SENT ppp3 NAPT)
14:26:45, 08 Jun. IN: ACCEPT [54] Connection opened (Port Forwarding: TCP [192.168.1.65]:4006 <--> [143.159.XXX.XX]:55299 - - - [185.176.27.178]:40210 CLOSED/SYN_SENT ppp3 NAPT)
It appears that the firewall is allowing an incoming connection and setting up port forwarding between port 4006 on my PC and port 40210/55235 on a device with IP185.176.27.178/193.27.228.161. I checked both the destination IPs and both are registered to some obscure address based in Russia!! (see below) - Should I be worried?