I found in my logs the following... 2001-08-29 01:54:22 211.185.206.2 12.32.70.210 Tcp 21 21 IpHalfScan 12.32.70.210 2001-08-29 01:54:22 211.185.206.2 12.32.70.211 Tcp 21 21 IpHalfScan 12.32.70.210 2001-08-29 01:54:22 211.185.206.2 12.32.70.212 Tcp 21 21 IpHalfScan 12.32.70.210 2001-08-29 01:54:22 211.185.206.2 12.32.70.215 Tcp 21 21 IpHalfScan 12.32.70.210 2001-08-29 01:54:22 211.185.206.2 12.32.70.218 Tcp 21 21 IpHalfScan 12.32.70.210 2001-08-29 01:54:22 211.185.206.2 12.32.70.221 Tcp 21 21 IpHalfScan 12.32.70.210 2001-08-29 01:54:22 211.185.206.2 12.32.70.222 Tcp 21 21 IpHalfScan 12.32.70.210 It's doesn't say that the attack was blocked. Does anyone know why? Thanks, Greg Foulks, MCP NewFound Technologies, Inc. http://www.nfti.com Email: greg.foulks@xxxxxxxx Voice: 614.318.5036 Fax: 614.318.5005