We used to get those from our old ISP all the time. I called them repeatedly and was told I was crazy. Since we switched ISP's it's never happened again. My geuss was that they were scanning segments for services. Greg. -----Original Message----- From: nathansimpson@xxxxxxxxxxxxxxx Sent: Thursday, February 28, 2002 6:52 PM To: isalist@xxxxxxxxxxxxx; nathansimpson@xxxxxxxxxxxxxxx Subject: [isalist] All port scan attack from our DNS forwards http://www.ISAserver.org Hi, I just received an all port scan attack from the 2 forwarders which are entered on our internal DNS server. The forwarders are the DNS servers from a local ISP. Why would they be scanning us? Should we be suspicious? TIA Nathan Simpson ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: gmh@xxxxxxxx To unsubscribe send a blank email to leave-isalist-244273Q@xxxxxxxxxxxxx