Ad Widget

Collapse

Zabbix and ISA 2006:ISA Server detected an all port scan attack from my zabbix server

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • gospodin.horoshiy
    Senior Member
    • Sep 2008
    • 272

    #1

    Zabbix and ISA 2006:ISA Server detected an all port scan attack from my zabbix server

    Hey all, I have a problem

    There is a remote site with ISA 2006 Server as Internet gateway. There I monitor 6 Windows servers, including this ISA itself (and plan to add more, actually). I use active checks only.

    Problem is that Application eventlog in ISA constantly registers events like so:

    Event Type: Warning
    Event Source: Microsoft Firewall
    Event Category: Packet filter
    Event ID: 15105
    ISA Server detected an all port scan attack from Internet Protocol (IP) address 193.xx.xx.xx






    IP in the message is my Zabbix server's Internet Address.

    Up to 10000 of those messages could be generated in a single day if I turn on the vast majority of zabbix's active checks on monitored servers



    Any ideas what I can do in this situation?

    I use active checks, most of them are from default windows template plus I monitor windows logs. Port 10051 is used, which is opened on ISA in outbound direction.


    Thanks in advance
    Last edited by gospodin.horoshiy; 17-03-2009, 13:39.
    Zbx 2.0.4 on Debian and MYSQL5 on Ubuntu Server 64bit 8.04,
    200+ Win Agents, 50+ Linux Agents, 150+ Network Devices
  • bbrendon
    Senior Member
    • Sep 2005
    • 870

    #2
    Let me guess, you have version 1.4.x agents?

    If you can't figure out how to make ISA shut up, upgrade to 1.6 agents and that message might/should disappear.

    Or maybe you server is compromised? Or chuck it up to a M$ feature.
    Last edited by bbrendon; 19-03-2009, 07:24.
    Unofficial Zabbix Expert
    Blog, Corporate Site

    Comment

    • gospodin.horoshiy
      Senior Member
      • Sep 2008
      • 272

      #3
      No, they all are 1.6.1 already
      Zbx 2.0.4 on Debian and MYSQL5 on Ubuntu Server 64bit 8.04,
      200+ Win Agents, 50+ Linux Agents, 150+ Network Devices

      Comment

      Working...