In the last two days I've gotten this email 4 times. I setup the alert
about 6 months ago but it's not been triggered until now. What does it mean
when the source is local to the server? There are two NICs in the server.
ISA Server name: CEISERVER
ISA Server detected a well-known port scan attack from Internet Protocol
(IP) address 127.0.0.1. A well-known port is any port in the range of
1-2048. For more information about this event, see ISA Server Help