Event Id | 15111 |
Source | POP Intrusion Detection Filter |
Description | ISA Server denied the assignment of the IP address 1 to the network adapter "2" since the IP address offered is not included in the "3" network IP addresses. This could indicate a possible DHCP attack. The Record Data contains the suspicious DHCP packet. |
Event Information | According To Microsoft: This event occurs when the DHCP anti-poisoning intrusion detection mechanism detects a malicious or invalid offer. Resolution: Follow the instructions provided in the description for the related alert. To do this, in the console tree of ISA Server Management , click Monitoring, then click the Alerts tab. In the list of alerts, select the relevant alert. The alert description displays in the alert details pane. |
Reference Links | Microsoft product: Internet Security and Acceleration Server Version: 4.0.3443.594 Event Source: POP Intrusion Detection Filter Event ID: 15111 |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.