So I recently got popped last month by my ISP for using double my allotted data for the month. After looking around and seeing other threads about this that essentially went unsolved or unreported as solved, I dug in deeper. What I found I can barely explain, but I'm wondering if its a security flaw. Im by no means an IT guy but I do have a decent home lab setup. I have an EdgeRouter 4, 24 port PoE Edgeswitch, a large media server that doubles as a Blue Iris machine and 4 UBNT UVC-G3 cameras. I looked into my bandwidth because Xfinity notofied me and Norton also did so requesting that I run their Power Eraser software due to abnormal amounts of outbound traffic. Kept digging and found that IP addresses from all over the world are logging into my Blue Iris web server and streaming my cameras. I'm obviously just looking for a solution so I can still use BI and not go over my data cap...and I do realize when nobody is viewing the feeds, it uses no bandwidth. I'll try to attach a couple screen shots of the switch, showing almost 40 Mbps at idle on port 3 for the camera server activity, and the log with one entry with a Polish IP address. Last week it was a Chinese IP address. I'm hoping someone can help me identify the problem. If I kill BI the bandwidth goes down to normal 5 Mbps with a video stream or two playing. They are logging in the web server and only being identified as "Server" with no credentials in the logs.



