I am updating my security log settings and testing some of the Advanced Logging features.
I have IPsec NPS on the network, so I am interested in any IPsec failures.
On my domain controllers I am getting lots of 4653 events:
The ones I am interested in are from IP addresses outside my network:
213.254.249.15, Microsoft Internet Data Center
95.100.255.62, AKAMAI-PA
84.53.139.66, AKAMAI-PA
88.221.212.79
213.254.249.15
72.21.80.5 etc
Can anyone enlighten me as to what these are?
I have other events which I understand
- some are misconfigured IPv6 local events
- some are from a new computer
CarolChi