Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

All port attach Alert

Status
Not open for further replies.

benfolds

Technical User
Oct 16, 2002
13
0
0
US
Hello all

I am currently getting application warnings in event viewer;

“ISA Server detected an all port scan attack from Internet Protocol (IP) address 194.168.4.100. For more information about this event, see ISA Server Help. “

As well as DNS warnings;

“The DNS server encountered an invalid domain name in a packet from 81.144.183.3. The packet is rejected. “

I’m not overly concerned as I know that this is just someone taking pot shots. The question is, can I do anything to find out where this is coming from? I know that I can block specific ip’s, but I would expect that who ever this is would be spoofing.

Thanks in advance
 
It is normal attack most of the network enconutering. U can Idntify to which ISP this ip is allocated but again of no use . Someone would have spoofed the ip (in that case presnt technolgy cannot help you to identify that)
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top