ISA Server detected a ping of death attack. For more information about this event, see ISA Server Help.

Details
Product: Internet Security and Acceleration Server
Event ID: 15007
Source: ISA Server H.323 Filter
Version: 4.0.3443.594
Component: ISA Server Services
Message: ISA Server detected a ping of death attack. For more information about this event, see ISA Server Help.
   
Explanation
A possible ping-of-death attack was attempted against a computer protected by ISA Server. This event occurs when a large amount of information is appended to an Internet Control Message Protocol (ICMP) echo request (ping) packet. If this attack is successful, the computer crashes.
   
User Action
If logging for dropped packets is enabled, you can view details of this attack in the Firewall log in the log viewer. You can use this log to monitor any further intruder activity. To do this, in the console tree of ISA Server Management click Monitoring, then click the Logging tab. Then edit the log filter to view the relevant details. Take additional steps against intruder activity. For example, you may want to add access rules denying traffic from the source of the intrusion. To do this, in the console tree of ISA Server Management click Firewall Policy. Then, on the Tasks, tab click Create New Access Rule.

Related:

Leave a Reply