[isapros] Large number of dropped packets oon port 20100

  • From: "Glenn P. JOHNSTON" <glenn.johnston@xxxxxxxxxxx>
  • To: <isapros@xxxxxxxxxxxxx>
  • Date: Fri, 7 Jul 2006 08:46:57 +1000

 
Hi,
 
One of the ISA2004 servers I look after has been logging a large number of 
dropped packet destined for port 20100,originating from various address in the 
60.100.x.x range, although if it is some kind of attack, this well may be 
spoofed. This started Wednesday evening Sydney time.
 
It's like 200 - 300 packets a minute being logged as dropped.
 
I've searched on the internet and can find no reference to anything like a 
virus / worm / DNS attack etc that uses port 20100, and it's only one of my 
clients, I've check my connection at home, and other clients, not even a wiff 
of the same thing. if was some kind of broad attack, i would expect to see it 
on more than just 1 client.
 
Anyone any clues on what this might be ?
 
Regards
Glenn

Other related posts: