My BorderManager has been humming along nicely for quite some time,
protecting a school. No errors, no problems. There are no user
accounts in the eDir except for admin. This is not a file server, only
a BorderManager and HTTP Proxy. The only way I access this server is
occasionally with Remote Manager. Then all of a sudden I get this in
the Server Health Log File:

Sunday, 10-22-2006 2:46 am
Failed Logins Per Hour on server RAND01 was in a SUSPECT State
Current Value - 5
Peak Value - 5
Max Value - N/A
Current SUSPECT threshold = More than 4 Failed Logins and Critical
threshold = More than 12 Failed Logins
Current SUSPECT trigger delay = -1 and Critical trigger delay = -1

Sunday, 10-22-2006 2:47 am
Failed Logins Per Hour on server RAND01 was in a BAD State
Current Value - 63
Peak Value - 63
Max Value - N/A
Current SUSPECT threshold = More than 4 Failed Logins and Critical
threshold = More than 12 Failed Logins
Current SUSPECT trigger delay = -1 and Critical trigger delay = -1

Sunday, 10-22-2006 4:17 am
Failed Logins Per Hour on server RAND01 was in a SUSPECT State
Current Value - 6
Peak Value - 2105
Max Value - N/A
Current SUSPECT threshold = More than 4 Failed Logins and Critical
threshold = More than 12 Failed Logins
Current SUSPECT trigger delay = -1 and Critical trigger delay = -1

Sunday, 10-22-2006 4:18 am
Failed Logins Per Hour on server RAND01 has returned to the GOOD State
Current Value - 0
Peak Value - 2105
Max Value - N/A
Current SUSPECT threshold = More than 4 Failed Logins and Critical
threshold = More than 12 Failed Logins
Current SUSPECT trigger delay = -1 and Critical trigger delay = -1




What's going on? Was someone trying to hack in?

Bob