Dear list users, since several days we have a lot of log entries originating from various IP addresses looking like this: 08/08/2001 00:09:34.464 - TCP connection dropped - Source:195.219.121.17, 1429, WAN - Destination: our ip address, 80, LAN - 'Web (HTTP)' - Rule 0 08/08/2001 00:11:53.928 - TCP connection dropped - Source:195.55.190.134, 3585, WAN - Destination: our ip address, 80, LAN - 'Web (HTTP)' - Rule 0 08/08/2001 00:17:43.384 - TCP connection dropped - Source:195.144.38.219, 2950, WAN - Destination: our ip address, 80, LAN - 'Web (HTTP)' - Rule 0 08/08/2001 00:26:19.432 - TCP connection dropped - Source:195.58.181.178, 3026, WAN - Destination: our ip address, 80, LAN - 'Web (HTTP)' - Rule 0 3 of these 4 IP addresses run IIS Webserver. One seems to be down. Since this is a firewall log and I have no other logfiles it is hard to me to determine whether this could be Code Red. Has anybody got a log that looks the same or similar? TIA Philipp