Event Id | 15111 |
Source | DNS Intrusion Detection |
Description | ISA Server denied the assignment of the IP address %1 to the network adapter "%2" since the IP address offered is not included in the "%3" network IP addresses. This could indicate a possible DHCP attack. The Record Data contains the suspicious DHCP packet. |
Event Information |
According to Microsoft : CAUSE : This event occurs when the DHCP anti-poisoning intrusion detection mechanism detects a malicious or invalid offer. SOLUTION : Follow the instructions provided in the description for the related alert. To do this, in the console tree of ISA Server Management , click Monitoring, then click the Alerts tab. In the list of alerts, select the relevant alert. The alert description displays in the alert details pane. |
Reference Links | Event id: 15111 Source id:DNS Intrusion Detection |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.