Does the ISA server detects fragmented attacks. I happen to experience an Intruder is continuously able to perform port scan on the external Interface while having his source IP blocked both on the perimeter router and on the firewall as a packet filter deny rule. Any thoughts? Shiv NB: Firewall has IDS enabled and keeps sending alerts.