There was an alert in Event Viewer that ISA Server had detected an All Port Scan Attack etc. I looked in the logs, and around the same time, the packet filter log has different entries. Normally the "filter-rule" column says BLOCKED but then it changed to FRAGMENT during the time of this port scan.
I've searched and searched but cannot find what this means. According to Microsoft the column should either be 1 or 0. So what does FRAGMENT mean? I've checked and the settings are to only log blocked packets, but I'd welcome an explanation from anyone in the know about this kind of thing.
What should I look out for if someone had gained access?
Thanks for any help
Stuart
I've searched and searched but cannot find what this means. According to Microsoft the column should either be 1 or 0. So what does FRAGMENT mean? I've checked and the settings are to only log blocked packets, but I'd welcome an explanation from anyone in the know about this kind of thing.
What should I look out for if someone had gained access?
Thanks for any help
Stuart