timsson

Member | Редактировать | Профиль | Сообщение | Цитировать | Сообщить модератору опасны ли данные сообщаги в мониторинге исы?!в прнципе перевел и логически не вижу особой опасности,,,,но так для прафилактики решил ещё здесь спросить,,,как бы чтобы быть увереным на все 100! 1.Alert Information Description: The number of TCP connections per minute from the source IP address 192.168.2.79 exceeded the configured limit. ISA Server will not allow the creation of new TCP connections from this source IP address during a system-defined time period. By default, this time period is 1 min. This event indicates that this IP address probably belongs to a host that is infected by a worm and attempts to propagate the worm to other vulnerable hosts. See the product documentation for more information about ISA Server flood resiliency. 2. Description: ISA Server disconnected a non-TCP connection from 192.168.2.123 because the connection limit for this IP address was exceeded. Larger custom connection limits should be configured for the IP addresses of chained proxy servers and back-to-back ISA Server computers with a NAT relationship. 3.Description: The number of denied connections from the source IP address 192.168.2.79 exceeded the configured limit. This may indicate that the host is infected or is attempting an attack on the ISA Server computer. |