All Port Scan on ISA Server
- From: "Weiss, Robert" <WeissR@xxxxxxxxxx>
- To: ISAserver Discussion List <isalist@xxxxxxxxxxxxx>
- Date: Mon, 29 Oct 2001 16:45:21 -0500
I am running four stand alone ISA Servers in integrated mode. I am
occasionally receiving reports in my packet filter logs that port scans or
all port scans are detected from the external interface of that server. I
don't have anything useful in the Packet Filter logs. Any ideas on what
might be causing this?
Event ID: 15104
ISA Server detected a well-known port scan attack from Internet Protocol
(IP) address xxx.xxx.xxx.131. A well-known port is any port in the range of
1-2048. For more information about this event, see ISA Server Help.
Please cc your reply directly to weissr@xxxxxxxxxx
<mailto:weissr@xxxxxxxxxx> as I don't always read my ISA List postings.
Thanks!,
Robert Weiss
Manager, Network and Academic Systems
Philadelphia University
Office of Information Technology
215-951-2689
http://www.PhilaU.edu/OIT
Other related posts: