Usually, when i have my coffee break, i will go to starbucks. I use my laptop to check the internet-related stuffs, like email, weather, home servers' stuffs, etc. I always use the FREE internet at starbucks, which is provided by access points from some people who dont' set up properly. Those are open, free, and no need to use any keys at all.

Today, i was having my coffee break at starbucks. However, I believe some one was trying to sniff the traffic when I vpn'ed.
While I was having my coffee break, I initiated VPN (PPTP) to connect to my ISA box, which is the edge firewall. However, my ISA box warned me that there was ALL PORTS SCAN detected around the time after I vpn'ed.
I checked the log from ISA box, which details that the all scan port was initialized from 192.168.1.2 and my ip from free wireless is dhcp'ed 192.168.1.115. so we are on the same subnet.
How the hell can 192.168.1.2 initiate all ports scan after I vpn'ed? Sorry if i ask this question, I understand that when you wanna scan ports over the internet, you must use public ip, rite? but my case is that the initial port scan was on a class C, which is the same Ip range i got from free internet. and when you vpn to another location, the traffic is encrypted to both end, so how the hell can a 192.168.1.2 do a port scan to my ISA? and my private range is class A 10.x.x.x. mm....i m scratching my head to see what configurations i oversight....or anything I should be aware of....
any suggestions for me?????
thanks