MessageISA is picking up numerous attacks (couple times a day) and some of the IP addresses listed are my external DNS servers. Any suggestions as to why? Currently when a attack happens from an IP address more than once I create an IP Packet Filter to block all access to/from that IP address. Is there anything else I should be doing? Thanks, John