I get that sometimes from my internal DNS server; but mostly it is from spyware-infested workstations. ________________________________ From: Richard Morris [mailto:richard@xxxxxxxxxxxxxxxxx] Sent: Tuesday, July 26, 2005 3:25 PM To: [ISAserver.org Discussion List] Subject: [isalist] 15108 http://www.ISAserver.org Hello. I'm intermittently receiving a spoof attack warning from an IP that is on the internal LAN or from a VPN client, have done some reading but none of the criteria match. Anyone seen this scenario before? Ta. ------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Visit TechGenix.com for more information about our other sites: http://www.techgenix.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: dball@xxxxxxxxxxx To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist Report abuse to listadmin@xxxxxxxxxxxxx