[isapros] Re: Large number of dropped packets oon port 20100

  • From: "Thomas W Shinder" <tshinder@xxxxxxxxxxx>
  • To: <isapros@xxxxxxxxxxxxx>
  • Date: Thu, 6 Jul 2006 18:24:19 -0500

Looks like an APNIC block.

Any outbound connections to those sites?

Thomas W Shinder, M.D.
Site: www.isaserver.org
Blog: http://blogs.isaserver.org/shinder/
Book: http://tinyurl.com/3xqb7
MVP -- ISA Firewalls

 

> -----Original Message-----
> From: isapros-bounce@xxxxxxxxxxxxx 
> [mailto:isapros-bounce@xxxxxxxxxxxxx] On Behalf Of Glenn P. JOHNSTON
> Sent: Thursday, July 06, 2006 5:47 PM
> To: isapros@xxxxxxxxxxxxx
> Subject: [isapros] Large number of dropped packets oon port 20100
> 
>  
> Hi,
>  
> One of the ISA2004 servers I look after has been logging a 
> large number of dropped packet destined for port 
> 20100,originating from various address in the 60.100.x.x 
> range, although if it is some kind of attack, this well may 
> be spoofed. This started Wednesday evening Sydney time.
>  
> It's like 200 - 300 packets a minute being logged as dropped.
>  
> I've searched on the internet and can find no reference to 
> anything like a virus / worm / DNS attack etc that uses port 
> 20100, and it's only one of my clients, I've check my 
> connection at home, and other clients, not even a wiff of the 
> same thing. if was some kind of broad attack, i would expect 
> to see it on more than just 1 client.
>  
> Anyone any clues on what this might be ?
>  
> Regards
> Glenn
> 
> 
> 

Other related posts: