I've had a couple of these alerts from my TMG server this morning.. Forefront TMG detected a possible Internet Protocol (IP) half-scan attack from IP address 192.168.1.89. But haven't been able to ping/find the IP on my network so i'm not sure