This could be any number of things. It could be that someone is running
a web vulnerability scanner against you, it could be Code Red (or some
variant thereof), or it could be just a simple DDOS like you suggest.
Is there anyway you could send the attempted connection string or web
request
This is a hack, but it will get the job done.
You could setup your tripwire policy so that it will always generate an
error of some sort. That way you would always get a message, and if you
failed to get an error sent, then you would know that your system has
been fooled with. There are ways
I was not very impressed with it's ability to interop with a freeswan
gateway. Even with all the documentation out there for a Win2K -
Freeswan gateway to gateway connection, it was difficult (to say the
least) to even get them talking together. Take this all with a grain of
salt, because I was