Re: switch out modems for VPN
Yes, I am using IPsec VPN, and I noticed increased activity (VPN connection attempts, all failed) after the summer. First deployed filtering rules (/16 subnet of attacker) but was overwhelmed within a few weeks had 25 rules.
Things only calmed down once I disabled Radius and WireShark, and applied geo-rules to block/allow VPN traffic (ports). Then I took the hammer rule and not only blocked VPN ports, but all traffic from snoopers from around 10 subnets /32. Interestingly, now the logs show not a single failed phase1 or phase2, but lots of other ports being probed (blocked subnets) as mentioned in the article above.