On Wed, 03 Apr 2002 15:41:23 MST, Mike Lewinski <mikeat_private> said: > Since I am not a VPN expert, I'm wondering if anyone else can shed some > light on what might be going on here. Is this just a brain-dead VPN client > that's making bad assumptions about it's resolvers? Or is there something > more malicious going on? The traffic was picked up after a SYN flood to one > of the DNS servers led to further investigation. Been there, done that. Quite possibly a Windows box that has the little box checked for "Try to negotiate IPSec connection always" (am not a WIndows person, not sure exactly what it's labeled). -- Valdis Kletnieks Computer Systems Senior Engineer Virginia Tech
This archive was generated by hypermail 2b30 : Thu Apr 04 2002 - 11:10:00 PST