I am running four stand alone ISA Servers in integrated mode. I am occasionally receiving reports in my packet filter logs that port scans or all port scans are detected from the external interface of that server. I don't have anything useful in the Packet Filter logs. Any ideas on what might be causing this? Event ID: 15104 ISA Server detected a well-known port scan attack from Internet Protocol (IP) address xxx.xxx.xxx.131. A well-known port is any port in the range of 1-2048. For more information about this event, see ISA Server Help. Please cc your reply directly to weissr@xxxxxxxxxx <mailto:weissr@xxxxxxxxxx> as I don't always read my ISA List postings. Thanks!, Robert Weiss Manager, Network and Academic Systems Philadelphia University Office of Information Technology 215-951-2689 http://www.PhilaU.edu/OIT