FWIW I'm throwing this out for comments and any corrections. Below is a snippet from my ADSL (DSL-2750U) router log, when connected to an ISP...

So looking at the first entry, I guess my log is alerting me that the router internal firewall has blocked (SRC=) 159.0.132.30 from using source port (SPT=) 43269 to scan whether destination port (DPT=) 63254 is open. And such attempts to scan for open ports are tagged (MARK=0x8000000) by my router for QoS use if enabled. BTW I've censored DST - that's my present IP
IP Info (assuming GeoIP is correct) about 159.0.132.30 informs me...

Anyway I gather this is normal activity (going on in the background), and that the router's firewall is working okay. But I wonder what would happen if the firewall was turned off.

So looking at the first entry, I guess my log is alerting me that the router internal firewall has blocked (SRC=) 159.0.132.30 from using source port (SPT=) 43269 to scan whether destination port (DPT=) 63254 is open. And such attempts to scan for open ports are tagged (MARK=0x8000000) by my router for QoS use if enabled. BTW I've censored DST - that's my present IP
IP Info (assuming GeoIP is correct) about 159.0.132.30 informs me...
Anyway I gather this is normal activity (going on in the background), and that the router's firewall is working okay. But I wonder what would happen if the firewall was turned off.