Hi everyone; I have been receiving alerts from ISA server almost 50 times a day since I enabled packet filtering and notifications. just wanted to see if these are real attacks and what should be done about them. by the way my ISA server has been getting dynamic IP from the ISP and I haven't had any problems so far. but I suspect it might have something to do with this dynamic IP !!?? here is a sample of the logs, 2002-10-26 00:00:07 207.25.71.252 24.78.164.31 Tcp 80 5959 BLOCKED 24.78.164.31 2002-10-26 00:00:26 200.177.83.3 24.78.164.31 Udp 1046 137 BLOCKED 24.78.164.31 2002-10-26 00:00:32 207.25.71.252 24.78.164.31 Tcp 80 5959 BLOCKED 24.78.164.31 2002-10-26 00:01:20 207.25.71.252 24.78.164.31 Tcp 80 5959 BLOCKED 24.78.164.31 2002-10-26 00:01:42 24.78.165.44 24.78.167.255 Udp 137 137 BLOCKED 24.78.164.31 2002-10-26 00:01:43 24.78.165.44 24.78.167.255 Udp 137 137 BLOCKED 24.78.164.31 2002-10-26 00:01:45 24.78.165.44 24.78.167.255 Udp 137 137 BLOCKED 24.78.164.31 2002-10-26 00:01:46 24.78.165.44 24.78.167.255 Udp 137 137 BLOCKED 24.78.164.31 2002-10-26 00:02:58 207.25.71.252 24.78.164.31 Tcp 80 5959 BLOCKED 24.78.164.31 2002-10-26 00:04:58 207.25.71.252 24.78.164.31 Tcp 80 5959 BLOCKED 24.78.164.31 2002-10-26 00:05:04 207.25.71.252 24.78.164.31 Tcp 80 6227 BLOCKED 24.78.164.31 2002-10-26 00:05:05 207.25.71.252 24.78.164.31 Tcp 80 6227 BLOCKED 24.78.164.31 thanks for the help, Farshad