Is the Packet Filter Log Accessed by Monitor?
- From: "Will" <westes-usc@xxxxxxxxxxxxxx>
- Date: Wed, 23 Jul 2008 21:53:14 -0700
We had a spoof attack and unfortunately ISA 2004's eventviewer detail about
this is quite bad (too sparse to narrow in on the attack). The event
viewer message contains this line:
"If logging for dropped packets is set, you can view details in the
packet filter log."
Logging for dropped packets IS set. Where is the packet filter log
stored? Is this just the normal packet log you can view through Monitor?
I did not find the packets in question there when looking for any packet
with the identified Source IP. The packets with that IP as source that
were located were all normal traffic originating on the correct network
interface.
--
Will
.
- Prev by Date: Re: Error 721 when trying to VPN
- Next by Date: Back-end network
- Previous by thread: Re: Error 721 when trying to VPN
- Next by thread: Back-end network
- Index(es):