On Wed, 03 Apr 2002 15:41:23 MST, Mike Lewinski <mike_at_rockynet.com> said:
> Since I am not a VPN expert, I'm wondering if anyone else can shed some
> light on what might be going on here. Is this just a brain-dead VPN client
> that's making bad assumptions about it's resolvers? Or is there something
> more malicious going on? The traffic was picked up after a SYN flood to one
> of the DNS servers led to further investigation.
Been there, done that. Quite possibly a Windows box that has the little
box checked for "Try to negotiate IPSec connection always" (am not a
WIndows person, not sure exactly what it's labeled).
--
Valdis Kletnieks
Computer Systems Senior Engineer
Virginia Tech
- application/pgp-signature attachment: stored
Received on Apr 04 2002