Quantcast
Channel: Forefront TMG and ISA Server forum
Viewing all articles
Browse latest Browse all 3822

Log the source IP address

$
0
0

Hi,
Is it possible to logged the IP address of all incoming connection? we have an Exchang 2010 that is behind an TMG 2010 and on this exchange server I found a lots of event 4526 there. I can see that some one use a rendom user name and password to get access to this server, but in the event logs I cannot see the IP address of the source, so that I can block this IP from trying to access this mail server. in the logs I can see this:

D:\Program Files\Microsoft\Exchange Server\V14\ClientAccess\PopImap\Microsoft.Exchange.Pop3.exe

So I think they try to break in to the system trough the POP3 Service.

Is there anyway to log the IP of the source of these connections on the Exchange or TMG level?

Thanks 

 

 


Shahin


Viewing all articles
Browse latest Browse all 3822

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>