What are you seeing? port 80 traffic? port 25?

thousands of random connections sounds like web indexing to me.

-Dan

On Thu, 8 Nov 2007, David Hubbard wrote:


Just wondering if anyone else is seeing huge random
floods of traffic from:

inetnum:      202.96.51.128 - 202.96.51.255
netname:      MICROSOFT-CO
descr:        Microsft (China) Co.Ltd
country:      CN
admin-c:      CH455-AP
tech-c:       SY21-AP
mnt-by:       MAINT-CNCGROUP-BJ
changed:      [EMAIL PROTECTED] 20060926
status:       ALLOCATED NON-PORTABLE
source:       APNIC
changed:      [EMAIL PROTECTED] 20060926

On a nearly daily basis we see them randomly open
thousands of connections from a variety of addresses
in that block to multiple servers.  I've emailed
of coruse but that results in nothing.  Probably
will just end up blocking them.

Thanks,

David

Reply via email to