Hi,
Is it possible to logged the IP address of all incoming connection? we have an Exchang 2010 that is behind an TMG 2010 and on this exchange server I found a lots of event 4526 there. I can see that some one use a rendom user name and password to get access
to this server, but in the event logs I cannot see the IP address of the source, so that I can block this IP from trying to access this mail server. in the logs I can see this:
D:\Program Files\Microsoft\Exchange Server\V14\ClientAccess\PopImap\Microsoft.Exchange.Pop3.exe
So I think they try to break in to the system trough the POP3 Service.
Is there anyway to log the IP of the source of these connections on the Exchange or TMG level?
Thanks
Shahin