Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations derfloh on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

All port scan attack Errors from External DNS Server

Status
Not open for further replies.

Cat1

Technical User
Jul 14, 2002
73
GB
Hi,

I have a small network of around 30 Win2K computers with two domain controllers.

I have one ISA Server (which is our firewall) with two NICs - one internal, one external which attaches to a leased line via a ISP supplied Cisco router.

Thing is, i keep getting ISA alerts coming up:

"An Intrusion was attempted by an external user - ISA Server detected an all port scan attack from Internet Protocol (IP) address x.x.x.x."

I'm getting anything from two to fifteen a day, with the 'attack' appearing to come from our external DNS server (ie: the IP in the error is the DNS server's belonging to the ISP).

I've run searches all over the web & just can't find any information about this.... i've spoken to our ISP who don't know what it could be... Help?!

 
I get this same alert from ISA's intrusion detection, but I haven't researched it yet. I assumed it was a normal function of the DNS server that triggered the alert.
 
If it is from a (relatively) trusted server, then I wouldn't worry too much. Port scans are no big deal, and they happen all the time. As long as your firewall is properly set up to drop all those scans, then its no big deal. Make sure you're blocking all traffic except what you need, and you should be ok.

________________________________________
Check out
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top