Hi, the last weeks I get plenty of port scan alerts from the address 127.0.0.1. I had them never before. In the log files I have entries from lokalhost like this: Date Time 127.0.0.1 x.x.x.x Tcp 80 1864 BLOCKED x.x.x.x (x.x.x.x = public ISA IP) How can I find out the process which is triggering this traffic and these alerts? Thank you, Manfred