Looks like an APNIC block. Any outbound connections to those sites? Thomas W Shinder, M.D. Site: www.isaserver.org Blog: http://blogs.isaserver.org/shinder/ Book: http://tinyurl.com/3xqb7 MVP -- ISA Firewalls > -----Original Message----- > From: isapros-bounce@xxxxxxxxxxxxx > [mailto:isapros-bounce@xxxxxxxxxxxxx] On Behalf Of Glenn P. JOHNSTON > Sent: Thursday, July 06, 2006 5:47 PM > To: isapros@xxxxxxxxxxxxx > Subject: [isapros] Large number of dropped packets oon port 20100 > > > Hi, > > One of the ISA2004 servers I look after has been logging a > large number of dropped packet destined for port > 20100,originating from various address in the 60.100.x.x > range, although if it is some kind of attack, this well may > be spoofed. This started Wednesday evening Sydney time. > > It's like 200 - 300 packets a minute being logged as dropped. > > I've searched on the internet and can find no reference to > anything like a virus / worm / DNS attack etc that uses port > 20100, and it's only one of my clients, I've check my > connection at home, and other clients, not even a wiff of the > same thing. if was some kind of broad attack, i would expect > to see it on more than just 1 client. > > Anyone any clues on what this might be ? > > Regards > Glenn > > >