I have the same problem, all port scan attack is logged to eventlog every 15-20 min. ISA server Paket Filter log is full of blocked packets from either our external DNS server and from some other server I dont know. All the packet are directed to 53 port. Also I found a lot of Allow-rule records in Firewall log coming from our local computer to external one also to 53 port. ----- Original Message ----- From: "Elcio Favare" <elcio.favare@xxxxxxxxxxxxx> Sent: Wednesday, October 02, 2002 10:37 PM Subject: Re: All port scans from external DNS server... > Try to find out what port is been logged in your log files.