I've had many people go over our firewall and it appears to be solid.
Apparently not since you are getting those entries on your IIS.

I have never used that router, but I believe for anyone to help you would have to supply the network layout and your firewall rules!

Is the IIS box on the DMZ ( WAN2 ) port?
From the documentation, one of the default rules is
All traffic from the WAN to the DMZ is allowed.
Are your rules for the DMZ set up to override this? ( there are rules specific for wan2, and not just included in the LAN rules? )

The user guide suggests this is possible, though again, I have never used that router.