Re: EventID 21284



Well MAN!!
this nuisance has strained my every nerve!!!i am also getting IP Spoofing
attacks from APIPA range IPs and Public IPs :(
just before finishing the day off...i restarted three servers in safe mode
and ran trend micro's SYSCLEAN(which runs in DOS mode)...it did catch some
viruses but not again to my expectation b/c the severity of the issue....but
at clients side i caught numerous ones like PE_Sality.AL etc....i woul
check it on tuesday morning did the scan remove any virus or not...
Another weired thing happened...ISA Server 2006 is running on domain
controller, OK....all domain controller clients clock augmented by 1
hour...afterward clients failed to login...what i did is to demote the client
to workgroup and then join them again....!!!!!!!!!!!!!!!!!
as u mentioned that you used Spybot S&D..is it free to use..

"Phillip Windell" wrote:

"S H A R I Q U E" <SHARIQUE@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:FD29FD67-EB78-4969-9749-EE7DEAB26F48@xxxxxxxxxxxxxxxx

Please let me know in whether this attack is happening from outside since
it
shows source IP to be my public IP.Furthermore, which tool i should run to
detect malware.I ran Windows Malicious Software Removal Tool(march 2008),
it
detected Win32/MyWife.E!CME24 and Win32/Nuwar.B!ini and removed.Are they
causing the issue.

How in the world do you end up with Spyware/Malware on the ISA??

Stop using it for a workstation to browse the Internet. There are reasons
why,...by default,...ISA doesn't allow any traffic to and from itself and
does not allow internet browsing from itself. That is also why you aren't
supposed to install anything else on the ISA machine. It is a Firewall
Product and you should treat it just like you would a PIX, CheckPoint,
SonicWall, Watchgaurd, whatever,...you would not be browsing the internet
from those or installing anything on them.

Run multiple Spyware/Malware Tools on it. No single product does it all.
I use Spybot S&D and Adaware from Lavasoft.

Then run a quality AV product on it as well. Do a full deep scan.

--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/ISA2004_AccessRules.html

Troubleshooting Client Authentication on Access Rules in ISA Server 2004
http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-fd6eeb6cfa07/ts_rules.doc

Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/partners/default.mspx

Microsoft ISA Server Partners: Partner Hardware Solutions
http://www.microsoft.com/forefront/edgesecurity/partners/hardwarepartners.mspx
-----------------------------------------------------



.



Relevant Pages

  • RE: Web Pages Stall
    ... I understand that the internal clients can ... Ensure your SBS 2003 server have right network configuration. ... How to configure Internet access in Windows Small Business Server 2003 ... proxy port defined on ISA server, by default it is 8080 on SBS 2k3. ...
    (microsoft.public.windows.server.sbs)
  • Re: ISA Server Problems, please help
    ... > clients are unaffected, is it secureNAT clients which are affected? ... then checked Send the original host header to the publishing server instead ... > provided unrestricted internet access. ...
    (microsoft.public.windows.server.sbs)
  • Re: ISA Server Problems, please help
    ... Based on the rules you have listed, SecureNAT clients should only be allowed ... The All access rule for SBS Internet Users ... Web Proxy and/or Firewall Client ... > header to the publishing server instead of the actual one. ...
    (microsoft.public.windows.server.sbs)
  • Re: The Web site cannot be found - errors
    ... problems connecting with the internet. ... Internet Connection Wizard from the server. ... > files and ISA cache on all ...
    (microsoft.public.windows.server.sbs)
  • RE: Internet Usage Reports
    ... There is no other application on the SBS server box that can monitor ... internet activities as your needs rather than ISA server. ... Microsoft Internet Security and Acceleration Server 2004 is the ... Microsoft is providing this information as a convenience to you. ...
    (microsoft.public.windows.server.sbs)

Loading