>This looks like someone is sending syslogs from a TACACS
Not realy (tacacs is the host name), in fact, it is a backup authentication server, that doubles as a backup DNS. It has been working fine for years, and these packets appeared very recently. I'm sure MS DNS bears part of the fault as Len suggested, but want to know if someone did run into similar problem. Was this some type of attack on my DNS server ? Or something else. Today, everything is back to normal. Also, is 514/UDP the tacacs port ? The packets were directed to the DNS port, not the tacacs port. TIA ---------- Original Message ---------------------------------- From: Sanford Whiteman <[EMAIL PROTECTED]> Reply-To: [EMAIL PROTECTED] Date: Mon, 11 Feb 2002 17:25:23 -0500 >This looks like someone is sending syslogs from a TACACS >(dial-in/remote user authentication protocol) server to your Imail >server. > >Block syslog (514/UDP) from getting to your box from the outside or >see who else in your organization is trying to log to your box. > >Sandy > > >Please visit http://www.ipswitch.com/support/mailing-lists.html >to be removed from this list. > >An Archive of this list is available at: >http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ > Please visit http://www.ipswitch.com/support/mailing-lists.html to be removed from this list. An Archive of this list is available at: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
