Re: All port scans from external DNS server...

  • From: "Andrey Ivolgin" <aivolgin@xxxxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Thu, 3 Oct 2002 11:58:05 +0400

I have the same problem, all port scan attack is logged to eventlog every
15-20 min.
ISA server Paket Filter log is full of blocked packets from either our
external DNS server and from some other server I dont know. All the packet
are directed to 53 port.
Also I found a lot of Allow-rule records in Firewall log coming from our
local computer to external one also to 53 port.


----- Original Message -----
From: "Elcio Favare" <elcio.favare@xxxxxxxxxxxxx>
Sent: Wednesday, October 02, 2002 10:37 PM
Subject: Re: All port scans from external DNS server...


> Try to find out what port is been logged in your log files.




Other related posts: