Event Id | 15104 |
Source | ISA Server Streaming Filter |
Description | ISA Server detected a port scan attack from Internet Protocol (IP) address 1. A well-known port is any port in the range of 1-2048. |
Event Information | According To Microsoft: A possible well-known port scan attack was attempted against a computer protected by ISA Server. This event occurs when an attempt is made to scan ports on this computer in order to detect the services running on these ports. Resolution: If logging for dropped packets is enabled, you can view details of this attack in the Firewall log in the log viewer. You can use this log to monitor any further intruder activity. To do this, in the console tree of ISA Server Management, click Monitoring. In the Logging tab, edit the log filter to view the relevant details. Take additional steps against intruder activity. For example, you may want to add access rules denying traffic from the source of the intrusion. To do this, in the console tree of ISA Server Management, click Firewall Policy. On the Tasks tab, click Create Access Rule. |
Reference Links | Microsoft product: Internet Security and Acceleration Server Version: 4.0.3443.594 Event Source: ISA Server Streaming Filter Event ID: 15104 |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.