>This   looks   like   someone   is   sending  syslogs  from  a  TACACS

Not realy (tacacs is the host name), in fact, it is a backup authentication server, 
that doubles as a backup DNS.
It has been working fine for years, and these packets appeared very recently.
I'm sure MS DNS bears part of the fault as Len suggested, but want to know if someone 
did run into similar problem.
Was this some type of attack on my DNS server ? Or something else.
Today, everything is back to normal.
Also, is 514/UDP the tacacs port ? The packets were directed to the DNS port, not the 
tacacs port.

TIA

---------- Original Message ----------------------------------
From: Sanford Whiteman <[EMAIL PROTECTED]>
Reply-To: [EMAIL PROTECTED]
Date: Mon, 11 Feb 2002 17:25:23 -0500

>This   looks   like   someone   is   sending  syslogs  from  a  TACACS
>(dial-in/remote  user  authentication  protocol)  server to your Imail
>server.
>
>Block  syslog  (514/UDP)  from getting to your box from the outside or
>see who else in your organization is trying to log to your box.
>
>Sandy
>
>
>Please visit http://www.ipswitch.com/support/mailing-lists.html 
>to be removed from this list.
>
>An Archive of this list is available at:
>http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
>

Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Reply via email to