Event ID - 15111

Event Id15111
SourceFTP Access Filter
DescriptionISA Server denied the assignment of the IP address %1 to the network adapter "%2" since the IP address offered is not included in the "%3" network IP addresses. This could indicate a possible DHCP attack. The Record Data contains the suspicious DHCP packet.
Event InformationAccording to Microsoft

Cause:
This event occurs when the DHCP anti-poisoning intrusion detection mechanism detects a malicious or invalid offer.
Resolution:
Follow the instructions provided in the description for the related alert. To do this, in the console tree of ISA Server Management , click Monitoring, then click the Alerts tab. In the list of alerts, select the relevant alert. The alert description displays in the alert details pane.
Reference LinksEvent Id:15111 Source Id:FTP Access Filter

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.