mi potete aiutare a capire se sono stato bucato

Vi spiego cosa è successo alle ore 10:51 ho ricevuto questo messaggio:
Server Name: ERBANAS
IP Address: 192.168.1.10
Date/Time: 17.05.2019 10:51:09
Level: Warning
[Security] Added IP: [192.168.1.220] to ban list forever.
La cosa mi ha incuriosito e sono andato a cercare di capire chi avesse l'ip 192.168.1.220 prima di essere bannato.
Avendo attivato il servizio SYSLOG sono andato alla ricerca della stringa 192.168.1.220 ed ho trovato questo:
<38>1 2019-05-17T10:50:55+02:00 ERBANAS qlogd 10270 - - qlogd[10270]: conn log: Users: guest, Source IP: 192.168.1.220, Computer name: 192.168.1.220, Connection type: SAMBA, Accessed resources: ---, Action: Login OK
<38>1 2019-05-17T10:50:55+02:00 ERBANAS qlogd 10270 - - qlogd[10270]: conn log: Users: guest, Source IP: 192.168.1.220, Computer name: 192.168.1.220, Connection type: SAMBA, Accessed resources: ---, Action: Login OK
<36>1 2019-05-17T10:50:57+02:00 ERBANAS qlogd 10270 - - qlogd[10270]: conn log: Users: admin, Source IP: 192.168.1.220, Computer name: localhost, Connection type: FTP, Accessed resources: ---, Action: Login Fail
<36>1 2019-05-17T10:50:57+02:00 ERBANAS qlogd 10270 - - qlogd[10270]: conn log: Users: admin, Source IP: 192.168.1.220, Computer name: localhost, Connection type: FTP, Accessed resources: ---, Action: Login Fail
<36>1 2019-05-17T10:50:57+02:00 ERBANAS qlogd 10270 - - qlogd[10270]: conn log: Users: admin, Source IP: 192.168.1.220, Computer name: localhost, Connection type: FTP, Accessed resources: ---, Action: Login Fail
<38>1 2019-05-17T10:50:59+02:00 ERBANAS qlogd 10270 - - qlogd[10270]: conn log: Users: guest, Source IP: 192.168.1.220, Computer name: 192.168.1.220, Connection type: SAMBA, Accessed resources: ---, Action: Login OK
<38>1 2019-05-17T10:50:59+02:00 ERBANAS qlogd 10270 - - qlogd[10270]: conn log: Users: guest, Source IP: 192.168.1.220, Computer name: 192.168.1.220, Connection type: SAMBA, Accessed resources: ---, Action: Login OK
<36>1 2019-05-17T10:51:08+02:00 ERBANAS qlogd 10270 - - qlogd[10270]: conn log: Users: admin, Source IP: 192.168.1.220, Computer name: localhost, Connection type: FTP, Accessed resources: ---, Action: Login Fail
<36>1 2019-05-17T10:51:08+02:00 ERBANAS qlogd 10270 - - qlogd[10270]: conn log: Users: admin, Source IP: 192.168.1.220, Computer name: localhost, Connection type: FTP, Accessed resources: ---, Action: Login Fail
<36>1 2019-05-17T10:51:08+02:00 ERBANAS qlogd 10270 - - qlogd[10270]: conn log: Users: admin, Source IP: 192.168.1.220, Computer name: localhost, Connection type: FTP, Accessed resources: ---, Action: Login Fail
<28>1 2019-05-17T10:51:11+02:00 ERBANAS qlogd 10270 - - qlogd[10270]: event log: Users: System, Source IP: 127.0.0.1, Computer name: localhost, Content: [Security] Added IP: [192.168.1.220] to ban list forever.
Premetto che nella nostra rete accedono al massimo 10 indirizzi IP relativi alle persone che ci lavorano sopra.
Inoltre l'unico servizio aperto verso l'esterno è l'FTP e che l'admin FTP è chiuso l'accesso a tutte le cartelle e risorse.
Per quello che io riesco a capire qualcuno a cercato di scalare i servizi verso admin da SAMBA e da FTP.
Qualcuno mi puoi aiutare a capire cosa è successo e cosa fare per proteggermi?
Grazie
Roberto