Well, I have WAG160Nv2 and I have a 512 IDM Subscription, I configured it long ago enabling Email Alerts. Today, I was checking my email and noticed something strange, I received two emails from the modem with the Subject: Security Alert [F5:2F:0A] !! It is the first time that I receive such alerts. What surprised me is the content of the email:
No.001  Sun, 2011-07-10 12:19:42 - UDP Packet - Source:193.227.177.53 Destination:10.152.x.x - [Firewall Log-PORT SCAN]
No.002  Sun, 2011-07-10 12:19:42 - UDP Packet - Source:193.227.177.53 Destination:10.152.x.x - [Firewall Log-PORT SCAN]
No.003  Sun, 2011-07-10 12:19:42 - UDP Packet - Source:193.227.177.53 Destination:10.152.x.x - [Firewall Log-PORT SCAN]
No.004  Sun, 2011-07-10 12:19:42 - UDP Packet - Source:193.227.177.53 Destination:10.152.x.x - [Firewall Log-PORT SCAN]
No.005  Sun, 2011-07-10 12:19:42 - UDP Packet - Source:193.227.177.53 Destination:10.152.x.x - [Firewall Log-PORT SCAN]
No.006  Sun, 2011-07-10 12:19:42 - UDP Packet - Source:193.227.177.53 Destination: 10.152.x.x - [Firewall Log-PORT SCAN]
No.007  Sun, 2011-07-10 12:19:42 - UDP Packet - Source:193.227.177.53 Destination: 10.152.x.x - [Firewall Log-PORT SCAN]
No.008  Sun, 2011-07-10 12:19:42 - UDP Packet - Source:193.227.177.53 Destination: 10.152.x.x - [Firewall Log-PORT SCAN]
No.009  Sun, 2011-07-10 12:19:42 - UDP Packet - Source:193.227.177.53 Destination: 10.152.x.x - [Firewall Log-PORT SCAN]
No.010  Sun, 2011-07-10 12:19:42 - UDP Packet - Source:193.227.177.53 Destination: 10.152.x.x - [Firewall Log-PORT SCAN]
The IP: 193.227.177.53 is the IP address of the DNS Server assigned by IDM (i looked it up and it is ns4.idm.net.lb) to my modem and the destination IP (I masked it) is the IP address that the modem received by DHCP from IDM.

Do you think that this is a normal behavior from IDM? Are they performing port scans on clients?
It is stupid modem, maybe you just had a lot of DNS requests, and due improper NAT handling modem giving false alert.