Re: hacker attempts?



It is pretty hard to go from "something at this IP is sending packets to me"
to saying "I am getting hack attempts from this IP". Without the ability to
establish that going to the second is clearly valid, there is nothing one
can do, and even with it whether anything can be done usually depends
on the good will of those with the network where that IP lives.

You might want to search the MS website for the guidance on
using IPsec for "domain isolation".

Roger

"will~" <will@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:46FA62EA-D0C5-40F4-9B46-10EE523BC190@xxxxxxxxxxxxxxxx
Windows 2003 Server R2 standard edition with SP2, sitting behind SonicWall
firewall.

Recently, there are a lot of Alerts from SonicWall. Such as "IPSec
Authentication Failed" and "IPSEC Replay Detected" and some "Sub Seven
Attack
Dropped"

It appears that the source IP address causing the IPSec Authentication
Failed messgae is from the same source IP address. I do not recognise
this
IP address and upon checking the internet it seems to be originated from
another town.

The fact that these are logged in sonicwall shows these have been
detected.
However, please advice if these IP addresses can be blocked from within
windows server, so that in the event that they have gone past the firewall
they could not establish communication with the server?

If these are hacking attempts are there any authority that we can report
to?
Many thanks for your assistance.






.



Relevant Pages

  • Re: IPSEC Port
    ... How you do this depends on your firewall. ... If so, you'll have difficulty with IPSec (like, ... Windows Server 2003 has NAT-Traversal to help overcome NAT issues. ...
    (microsoft.public.windows.server.security)
  • IPSEC
    ... Can I use IPSEC as a Firewall in Windows Server? ... Athan ...
    (microsoft.public.windows.server.security)
  • Re: Win2K Security & Firewall - long post
    ... IPSec, and more so some reasons why it might be a bad idea for MS to ... realize that tailoring an IPSec policy for a specific home user, ... disabled their personal firewall. ... Won't work if the malware uses a "legitimate" means of disabling ...
    (comp.security.firewalls)
  • Re: Isolate systems
    ... some sort of port/protocol/Ip/mac"filtering" via switches, ipsec filtering, ... firewall yourself from outside the network, even if you use a self scan site ... If legitimate users are trying to attack your computers you may have to see ...
    (microsoft.public.win2000.security)
  • Re: sysvol replication breaks when IPSec running between DCs & fir
    ... IPSec" as per as per Steve Riley ... I do not know how to write a firewall rule to ensure that IP ... Riley says you can "Encapsulate domain controller traffic inside ... the IPsec exists underneath the Windows Firewall ...
    (microsoft.public.windows.server.active_directory)