Hi, In application log frequently i am seeing a event id with no 15108. In = that it has like this. ISA server detected a spoof attack from internet protocol (ip) address = XXXXXXXXXXX (which is my internal ip). A spoof attack occurs when an ip = address that is not reachable via the interface on which the packet was = received. If logging for dropped packets is set, you can view details in = the packet filter log. Pl. tell me what is the solution for this problem. Gops