your assessment makes sense… getting rid of all the guest SIP noise in the logs made it a lot easier to look through them…
I am definitely looking to lock down higher up the chain… once the firewall only allows traffic from approved sources… I don’t expect this to be an issue again…