All Port Scan Attack from DNS Ip Address

  • From: "Becker1" <becker1@xxxxxxxxxxxxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Wed, 21 Nov 2001 09:14:25 -0800

MessageISA is picking up numerous attacks (couple times a day) and some of the 
IP addresses listed are my external DNS servers.

Any suggestions as to why?

Currently when a attack happens from an IP address more than once I create an 
IP Packet Filter to block all access to/from that IP address.

Is there anything else I should be doing?

Thanks, John

Other related posts:

  • » All Port Scan Attack from DNS Ip Address