<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Using Netmon 3.2 to Identify an Unexpected Traffic</title><link>http://blogs.technet.com/yuridiogenes/archive/2008/10/19/using-netmon-3-2-to-identify-an-unexpected-traffic.aspx</link><description>1. Understanding the Problem I already worked in many cases where customer wants to know why ISA is alerting that it might be under attack by logging events such as: Figure 1 – Number of TCP Connections. …and also this one: Figure 2 – Denied Connections</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator></channel></rss>