Have a nice read: http://www.microsoft.com/technet/community/columns/sectip/st1205.mspx ________________________________ From: isapros-bounce@xxxxxxxxxxxxx on behalf of Glenn P. JOHNSTON Sent: Thu 7/6/2006 3:46 PM To: isapros@xxxxxxxxxxxxx Subject: [isapros] Large number of dropped packets oon port 20100 Hi, One of the ISA2004 servers I look after has been logging a large number of dropped packet destined for port 20100,originating from various address in the 60.100.x.x range, although if it is some kind of attack, this well may be spoofed. This started Wednesday evening Sydney time. It's like 200 - 300 packets a minute being logged as dropped. I've searched on the internet and can find no reference to anything like a virus / worm / DNS attack etc that uses port 20100, and it's only one of my clients, I've check my connection at home, and other clients, not even a wiff of the same thing. if was some kind of broad attack, i would expect to see it on more than just 1 client. Anyone any clues on what this might be ? Regards Glenn All mail to and from this domain is GFI-scanned.