On 9 Feb 2016, at 9:50, mike.lyon at gmail.com wrote: > Sounds like there is a compromised host downstream of the 1G that is > reporting back it's source IP and that is why changing the IP doesn't > help. It's much more likely that the attacker is just following the DNS changes. ----------------------------------- Roland Dobbins <rdobbins at arbor.net>