What are you seeing? port 80 traffic? port 25?
thousands of random connections sounds like web indexing to me. -Dan On Thu, 8 Nov 2007, David Hubbard wrote:
Just wondering if anyone else is seeing huge random floods of traffic from: inetnum: 202.96.51.128 - 202.96.51.255 netname: MICROSOFT-CO descr: Microsft (China) Co.Ltd country: CN admin-c: CH455-AP tech-c: SY21-AP mnt-by: MAINT-CNCGROUP-BJ changed: [EMAIL PROTECTED] 20060926 status: ALLOCATED NON-PORTABLE source: APNIC changed: [EMAIL PROTECTED] 20060926 On a nearly daily basis we see them randomly open thousands of connections from a variety of addresses in that block to multiple servers. I've emailed of coruse but that results in nothing. Probably will just end up blocking them. Thanks, David
