As per Microsoft: "The dropped packet rate of some special kinds of packets (for example, spoofed packets or fragments) exceeds the rate specified in the configuration for dropped packets. To configure the drop rate, in the ISA Management console tree, click Servers and Arrays, click Name, click Monitoring Configuration, click Alerts, and then click Dropped packets alert properties. Examine the packet filter logs to detect the nature of the drop rate and take further action."