Is the Packet Filter Log Accessed by Monitor?



We had a spoof attack and unfortunately ISA 2004's eventviewer detail about
this is quite bad (too sparse to narrow in on the attack). The event
viewer message contains this line:

"If logging for dropped packets is set, you can view details in the
packet filter log."

Logging for dropped packets IS set. Where is the packet filter log
stored? Is this just the normal packet log you can view through Monitor?
I did not find the packets in question there when looking for any packet
with the identified Source IP. The packets with that IP as source that
were located were all normal traffic originating on the correct network
interface.

--
Will


.