Problem is bizarre, at least to me.
I have a windows 2003 dedicated server. Every now and then (approx every three months), Cisco switch disconnects this server like so:
%PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occurred, caused by MAC address 2020.2020.3c64 on port FastEthernet0/33.
ISP's support is trying to convince me that I have some malware that is trying mac spoofing attack, and that it is their policy to allow 3 mac addresses per port and that this occurs when this address limit is exceeded.
I've scanned with three different tools (including Microsoft's) and I can not find anything. I've checked web access logs around time when this happens, and there's not even script kiddies looking for phpmyadmin.
Could it be that some windows component is doing this? Any, and I do mean ANY advice on what to check next would be appreciated.