Intermittent Firewall 15108 Events on SBS2003/ISA2004



I'm getting a small number of 15108 events around the times when a remote user connects through VPN.

Our internal LAN IP addresses are 10.0.0.x.

Most of the 15108s quote IP addresses in the 10.0.0.11 to 10.0.0.17 range - all allocated to the server, according to DHCP.

The other 15108 quotes 192.168.2.2 which I believe is the remote client's IP address connecting to the remote ADSL Modem/Router (client connects via a VPN dial-up).

Not experiencing any abnormal behaviour connecting or working remotely so should I be doing anything about these messages?

And why does Firewall flag up 15108s for addresses allocated to the server?

Further info:

1. Internal address range in ISA is 10.0.0.0 to 10.0.0.255 plus 10.255.255.255. DHCP address pool has 10.0.0.1 to 10.0.0.254 with 10.0.0.1 to 10.0.0.9 excluded (and 10.0.0.113 which is reserved for a network printer).
2. Internal server IP (10.0.0.2) has no default gateway and only DNS entry is 10.0.0.2.
3. External server IP is 192.168.0.2 with default gateway 192.168.0.1 (ADSL Router). DNS is set to 10.0.0.2.
4. DNS has forwarders pointing to our ISP's primary and secondary DNS servers.
.




Relevant Pages

  • Re: Setting Up LMHost File? (DNS problem on VPN).
    ... We have around 17 remote sites so using a DC for each would be expensive, and I can't see a benefit at the moment. ... also the DNS server. ... which includes the DNS. ... We really need a lot more info about the setup. ...
    (microsoft.public.windows.server.networking)
  • Re: Setting Up LMHost File? (DNS problem on VPN).
    ... We have around 17 remote sites so using a DC for each would be ... also the DNS server. ... which includes the DNS. ... We really need a lot more info about the setup. ...
    (microsoft.public.windows.server.networking)
  • Re: DNS Forward lookup problem - now having problems with a period
    ... How did you set the replication scopes in the zone's properties in DNS on ... > each DNS server? ... to the remote 10.0.2.3 server, which runs on cable (we are working on ...
    (microsoft.public.windows.server.dns)
  • One Post to Sum It All Up
    ... I am not suure I have my DNS configured conrrectly. ... aslo have a DNS server in the Internal Segment which is my Active Directory ... consolsrv01 A 10.0.0.2 ... Remote Desktop / Terminal Services ...
    (microsoft.public.win2000.dns)
  • Re: Windows 2003 standard permissions
    ... Not sure what you mean by adding a subnet to your DNS server. ... If you mean add a reverse lookup zone for the IP set of the remote ... Microsoft MVP (Windows Server System: ...
    (microsoft.public.win2000.security)