I get a new ip now, (dhcp), and it keep on try arp a lot of ip, them about 20 mins later the icmp flood report from black ice come back again. funny. Thx your guys any way.
It 's just a dot net test server. so doesn't matter. I plan to reinstall the system.
w2k + sp1 (without index server)+ dot.net platform + blackie 2.5
can not prevent attacking.
be careful guys.