    On Wed, 03 Apr 2002 15:41:23 MST, Mike Lewinski <mikerockynet.com> said:

    > Since I am not a VPN expert, I'm wondering if anyone else can shed some
    > light on what might be going on here. Is this just a brain-dead VPN client
    > that's making bad assumptions about it's resolvers? Or is there something
    > more malicious going on? The traffic was picked up after a SYN flood to one
    > of the DNS servers led to further investigation.

    Been there, done that. Quite possibly a Windows box that has the little
    box checked for "Try to negotiate IPSec connection always" (am not a
    WIndows person, not sure exactly what it's labeled).

