[general] SP2 Tweak 2 get rid of TCP/IP limit


Recommended Posts

The beta testers noticed this (from what I was told) in the final stages of SP2. SP2 will limit the max number of TCP/IP connections that can be made to another computer via ONE port simultaneously to 10. Example : you can have 10 connections to 123.123.123.123 on port 234, but no more. Before this it was unlimited (well it wasn't really unlimited, but I call 16.7 million unlimited ). Their motivation? To stop (1) Port scanning (2)DoS attacks (3)(just a guess) to hurt P2P file sharing and thats bad. Know why? Because who knows what else that will hurt (proxies anyone?) and I don't like knowing there is a cap on my potentiol! How do you fix it?

Discussion about the issue can be found @ http://www.m$fn.org/board/index.php?showtopic=22640

Read instructions on HOW to apply the patch (below) @ http://www.m$fn.org/board/index.php?s...20entry162131

Download the patch so that you don't get the SP2 limit @ http://www.supportbuddy.com/sp2/tcpip.sys (NOTE : The TCPIP.sys file used was from from XP SP2 RTM (build 2180))

The guide as to how the patch was created can be found @ http://www.lvllord.de/4226fix/4226fix-en.htm

EDIT : I don't know why those first two links arent shoinwg up right go here ==> http://forums.pcper.com/showthread.php?t=342126 for the links in proper form (i posted this at another forum too, thats what this link is :D )

EDIT 2 : I got the links working. I had to go read why they weren't showing up. I didn't even know yall hated each other. Anywho, its obvious that you gotta replace teh $ with an S.

Edited by nytmarezz

Get hold of a boot cd with Winternals or Bart's PE Builder or Hiren's Boot CD Ver6 and go to a restore point, once you boot from the cd, and see if this will solve the problem.

Sorry this was ment for someone else. Wrong place, sorry!!!

i just used the patch which increases it to 50 from neowin from the following link

https://www.neowin.net/forum/index.php?showtopic=200828

is that OK? the link for the file i used is

https://www.neowin.net/forum/index.php?act=...st&id=584323888

,Aug 9 2004, 23:37] weird...I haven't noticed any slowdown with torrents since saturday, when I installed RTM. I think I'll wait until more details about this come to light.

same here. I have been using a recent post-SP2 build but neither bittorrent or emule where slow.

just wondering, 1. why would a p2p application on one computer connect 10 times to another computer on the same port?! 2. why did u put those $ in the links?

Actually WindowsXP itself was limited to 10 connections. This was to keep someone from using WinXP as a server rather than buy Windows Server. You can overcome this by modifying the registry, but in most cases is not necessary as no one wants to use WinXP as a true server so doesn't need anymore connections than this.

If you aren't comfortable editing the registry try X-Teq'a XSetup, very nice program with an intuitive interface.

I think the patch is a mistake. Many people who don't know what it actually does, and don't need it, will just apply the patch and will make things worse instead of improving them! Very few people need this patch. The average joe should not install this patch blindly.

I like the conspiracy theories about P2P though. The patch does not limit the connections to 10, it puts all >10 in a queue where they are still processed, but with a slight delay. The effect to anyone but a worm who opens bazillions connections a minute is not noticeable.

Also quite funny that people keep ranting that MS doesn't do enough for security, and when they finally do everyone goes OMG and reverses the whole thing. And in a week they will rant that MS doesn't do enough about security.

If you still feel that you need this patch, get the one that limits at 50, not the one that removes the limit completely!!

50 is still a reasonable limit, and might still hurt worms at least a bit, but is surely relaxed enough to not even affect the most connection happy guy on this planet ;) While unlimited is ... unlimited ;)

All i'm saying is don't apply the patch just because everyone seems to do. If you run into noticeable problems and are absolutely positively sure that SP2 makes whatever you do much slower then by all means go ahead and try it out. Don't get freaked out because 4622 appears in the event log, that alone is not a sign of anything becoming slower.

Hi,

To clarify, this restriction is for HALF OPEN TCP connections only, not the total number of TCP connections your PC can or will make.

A half open connection is one which has not yet completed the full TCP hand-shake sequence.

If an application has issues with limiting the rate at which connections can be made, then the authors need to take this into account in future releases.

In theory XP SP2 will cache the pending TCP connections until they have been completed, if your application needs 50 connections and there are 10 still pending, the other 40 will be cached and processed when the queue clears. This rate will depend on what your application is connecting to :)

Please don't think this limits the total number of TCP connections you can make, it just affects the RATE at which they can be processed.

It has no other effects on network shares or other forms of connections.

Unless you have an application which is seriously impacted by this limit, I would suggest this limit is not changed. If you have a application which is being affected, you need to send feedback to the author so that can amend the software to make it SP2 complient :)

Kind Regards

Simon

It affects the rate.. yes! So it also affects filesharing clients.. If you prefer security above download speed, ok.. but I don't.. I just don't want the SP2 change, but the way it was in SP1, so unlimited and not only 10!

When you don't apply this patch.. you are not able to connect to servers like in Shareaza.. When you only have a few downloads in your list, then there is not really a problem, BUT when you are a heavy user and have many downloads, then 10 and even 50 concurrent connections is not enough.. I just don't want to see the EventID error at all.. because that means the capabilities of the application are getting hammered..

This is what Microsoft says:

Limited number of simultaneous incomplete outbound TCP connection attempts

Detailed description

The TCP/IP stack now limits the number of simultaneous incomplete outbound TCP connection attempts. After the limit has been reached, subsequent connection attempts are put in a queue and will be resolved at a fixed rate. Under normal operation, when applications are connecting to available hosts at valid IP addresses, no connection rate-limiting will occur. When it does occur, a new event, with ID 4226, appears in the system?s event log.

Why is this change important? What threats does it help mitigate?

This change helps to limit the speed at which malicious programs, such as viruses and worms, spread to uninfected computers. Malicious programs often attempt to reach uninfected computers by opening simultaneous connections to random IP addresses. Most of these random addresses result in a failed connection, so a burst of such activity on a computer is a signal that it may have been infected by a malicious program.

What works differently?

This change may cause certain security tools, such as port scanners, to run more slowly.

How do I resolve these issues?

Stop the application that is responsible for the failing connection attempts.

Stop the application? Does Microsoft think we are stupid?

No, if you don't want to be restricted in any way, than this is for you.. If you don't care, just don't apply this patch.. it's as simple as that..

I modified the TCPIP.SYS.. just follow the instructions below, after that it's not 50 anymore, but unlimited!

* patched file attached *

This fix will make the number of concurrent TCP connect attempts UNLIMITED.

Instructions:

First of all, make sure you backup your old tcpip.sys first!

Restart your computer an press F8 short after the Bios is done and start in safe mode.

Then we go into the directory C:\WINDOWS\SYSTEM32\DRIVERS and overwrite the existing TCPIP.SYS

with our patched one and then repeat this with the directory C:\WINDOWS\SERVICEPACKFILES\I386

and system dependend eventually with C:\WINDOWS\SYSTEM32\DLLCACHE.

We did it! Now only reboot Windows and the normal surfing will work again!

The original fix was made by LvlLord, but that fix only increases the number of concurrent TCP connect

attempts from 10 to 50 which is in some cases not sufficient.

http://www.lvllord.de/4226fix/4226fix-en.htm

Edited by FBtje

People just don't understand. Notice what it says dude. INCOMPLETE TCP connections. As stated numerous times before this will not hender filesharing.

Besides this is not a discussion for the AutoPatcher forum and I hope a moderator will move or close this discussion.

Well I noticed that in shareaza I just cannot connect to the Gnutella1 servers..it will gave various reasons but the common thing is that I just _won't_ be able to connect to Gnutella 1 network, I thoguht this patch may fix that..but apparently not. Is this issue related?

it can take a considerable amount of time before G1 gets connected.. just be patient ;)

at least make sure your host cache for Gnutella1 is not empty (menu -> View -> Host Cache).. if it's empty try to query some services by pressing F9, also deleting all services first will sometimes help..

People just don't understand.  Notice what it says dude.  INCOMPLETE TCP connections.  As stated numerous times before this will not hender filesharing. 
I just don't like limits even if they are practical.
Besides this is not a discussion for the AutoPatcher forum and I hope a moderator will move or close this discussion.

I put it here in the autopatcher forum so that if Flish or Raptor want to include it as an optional tweak in Autopatcher (that would rock!) then at least they know about it. There are lots of other similar little tweaks in the full version of autopatcherxp.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • We could disable web results as far back as Windows 10 everywhere.
    • No, it wasn't "huge", it is lame, and it was lame back then.
    • 7 Days: SPECS for $2,195, Firefox Nova 2026, first AI arts museum, and iPhone price hike by Aditya Tiwari 7 Days is a weekly roundup of picks of what's been happening in the world of technology - written with a dash of humor, a hint of exasperation, and an endless supply of (black) coffee. This week's highlights include Linux 7.1 stable release, Samsung pulling the plug on its VPN, and Microsoft Edge bringing the sign-in with Google experience. Let's get started. You can check out the recent issues of the 7 Days weekly roundup. Mozilla highlights Firefox Nova Mozilla showed off a new Firefox roadmap highlighting the browser's upcoming features and the Nova 2026 redesign. Interested users and enthusiasts can check out what's cooking and share feedback on the upcoming additions. Besides this, Firefox 152 brought Tab Groups to Android as one of its biggest additions, along with a redesigned Settings experience. World's first AI arts museum Image: Google Google opened the world's first AI arts museum in Los Angeles on June 20, which it named Dataland. The museum, spanning 25,000 square feet, was built in collaboration with media artist Refik Anadol, who has worked with Google since 2016. It will have real-time visuals and react dynamically to visitors. Salesforce shopping bag In the latest acquisition news, Salesforce is buying the customer support software company Fin (formerly Intercom) for $3.6 billion to strengthen its AI customer service ambitions and Agentforce platform. The transaction is expected to close in the fourth quarter of its fiscal year 2027. UK follows Australia Prime Minister Keir Starmer announced that the country will ban social media for kids under 16, which is happening after a six-week trial involving 300 teenagers, stating that social media is making them unhappy and easier for bullies to harass and abuse them. Starmer continued that social media is addictive and uses an infinite scroll designed to lock users in for hours. The UK government plans to take action on gaming services and livestreaming platforms. Meanwhile, its age verification rules have also become a hot topic and a point of criticism. Our Features Our coffee-powered team publishes a platter of editorials, opinion posts, and guides. Check them out: Microsoft hides these secret Windows 11 performance boost settings available on every PC Microsoft Paint used to be my favorite Windows app as a kid, and it's still pretty good Why you need to take back control of your synced passwords and how to go about doing that The Microsoft Office feature that time forgot This week in software news Catch up on some of the latest software news updates that arrived throughout the week: Another Samsung shutdown: The South Korean giant is pulling the plug on the Samsung Max VPN app, which is used by more than 50 million users. The app has stopped working since June 15, and Samsung didn't provide a reason for the unexpected move. Photoshop power-up: The popular image editing app is getting a big 20% performance boost on x86-64 (AMD64) systems and a 13% bump-up on Arm devices. Here, the credit goes to a new performance boost added to Windows 11 following a combined effort between Microsoft and Adobe. Linux 7.1 arrives: Linus Torvalds released the stable Linux 7.1 kernel this week, which brings critical driver updates and a rewritten storage driver. You should look out for the new NTFS driver, Intel FRED for improved performance on Panther Lake and future CPUs. Ads in your games: Electronic Arts is launching a new advertising platform to serve in-game ads and enable brands to feature their products in titles like EA Sports FC, Madden, NHL, Skate, or The Sims. With EA Advertising, brands will be able to inject their products into games in real-time via dynamic placement, in places like stadium signage in sports games. Sign in with Google: Microsoft Edge browser is finally getting direct Google account sign-in support from the profile menu and the Edge sign-in screen, allowing users to sync browser data without an MSA. Rufus 4.15 beta: The latest Rufus update is out with important fixes for "silent" Windows 11 installation, patches for ARM-based PCs, and more. Rufus 4.15 beta is now available to download from its official GitHub repository. NVIDIA 610.62: GeForce hardware owners can get their hands on the new WHQL-certified 610.62 Game Ready driver, which carries a lot of bug fixes and support for the fast-paced 6v6 movement shooter Empulse. Zed 1.7.2: The latest update adds "/compact" AI chat summarization, new models, settings kill management, git graph commands, and UI improvements. This week in hardware news Image: Snap Inc. Catch up on some of the latest software news updates that arrived throughout the week: SPECS for $2,195: Snap Inc. launched its new AR-powered wearable computer. SPECS are now available for pre-order and will start shipping in the US, UK, and France later this year. No CMF phone in 2026: The global memory shortage has also knocked Nothing's door and it has decided to hold the launch of CMF Phone 2 Pro's successor this year. That said, Nothing still has planned several new products under the CMF brand. 12th Gen Surface Pro: It's been two years since the original pair of Copilot+ PCs arrived. Now, Microsoft upgraded the lineup with Snapdragon X2-based devices for the 12th-gen Surface Pro, which promises up to 53% faster graphics. New Surface Laptop: The refreshed Surface Laptop is also powered by the Snapdragon X2 Plus and X2 Elite, offering up to 58% faster graphics performance, 80 TOPS Neural Processing Units (NPUs), and up to 20 hours of battery life. HONOR Robot Phone: The Chinese smartphone maker demoed its mobile photography capabilities by capturing its first cinematic video using the Robot Phone concept, which features a 3-axis, 4DoF gimbal that extends from the phone's body for stable recording and real-time subject tracking. Snapdragon Reality Elite Platform: Qualcomm's new platform is a massive leap forward for mixed reality and spatial computing devices. It can power both all-in-one video-see-through headsets and lightweight, tethered optical-see-through glasses, offering better visuals, improved power efficiency, and deeper on-device AI integration compared to the previous generation. Galaxy XR: Samsung's extended-reality handset arrived in the UK months after its launch. It's available for pre-order now and will go on sale on July 8. The hardware remains unchanged, but Samsung has pushed several new updates in recent months. HONOR Watch 6: HONOR also launched its new smartwatch with an incredible 35-day battery life without breaking your bank. The device is made from recyclable aluminum alloy and weighs just 41 grams. Where are the foldables? If you're waiting for Samsung's fresh lineup of foldable devices, you can read Hamid's detailed post about the Galaxy Z Fold8, Flip8, and Z Fold Wide, a passport-style device expected to rival the foldable iPhone. This week in Google News Image: Google Catch up on some of the latest Google and Alphabet news updates that arrived throughout the week: Gemini co-lead departs: Noam Shazeer, who served as VP of engineering and technical co-lead for Gemini, is leaving the search giant for OpenAI. Shazeer is best known as one of the co-authors of the 2017 "Attention Is All You Need" paper, which introduced the Transformer architecture that now powers most LLMs. Waymo recall: The Alphabet-owned self-driving car maker recalled its fifth-generation Automated Driving Systems (ADS) after multiple cars drove through closed construction zones. The NHTSA website said Waymo is currently working on a fix, and freeway driving is being restricted. This week in Apple News Image: Apple Catch up on some of the latest Apple news updates that arrived throughout the week: Tim Cook confirms price hike: The departing Apple CEO confirmed the looming price hikes for Apple's future products without naming any, adding that “Unfortunately, price increases are unavoidable.” Despite having cash and silicon expertise, Apple has no plans to build its own memory and storage factories. An educated estimate suggests customers could end up paying around $1,299-1,399 for the base iPhone 18 Pro. iPhone Air isn't dead: If you were thinking the iPhone Air has lived its life, a new report claims otherwise. The next iPhone Air (codenamed V62) is expected to arrive in the spring of 2027, featuring an additional rear camera for ultrawide photography and improved battery life to address its biggest drawbacks. This week in Meta news Catch up on some of the latest Meta, WhatsApp, and Instagram updates that arrived throughout the week: A long-requested feature: Instagram has finally enabled users to write individual captions for each image or video in a carousel. Rolling out to all users, you can select "Multiple Captions" option from the dropdown while creating a carousel in the app. Threads reaches new milestone: Meta's text-first social media platform crossed 500 million monthly active users. It's now expanding the Communities feature beyond beta, adding a new set of tools to make participation easier and more engaging. This week in AI news Image via DepositPhotos.com Catch up on the latest artificial intelligence news updates that arrived throughout the week: Unreal Engine 6: Epic Games' upcoming engine brings changes to the programming model, portability improvements, and generative AI integration. It focuses on the use of generative AI models and tools like Claude and Codex to play a central role in helping developers "build content faster." Americans and AI: New research suggests that about 49% of American adults use AI chatbots such as Gemini and ChatGPT. However, many are skeptical about the impact of AI on both the personal and societal levels, believing it may be harmful in the long run. Mainframe exit vendors might exit: Gartner predicts in its new report that 75% of mainframe exit vendors, which help companies migrate their legacy mainframe systems to modern cloud environments, will either pivot or cease operations as the market realities take hold by 2030. This week in Microsoft News Microsoft announced Windows 11 version 26H2; confirmed a new bug where the Recycle Bin delete prompts display internal file names instead of actual ones; the latest Patch Tuesday updates seemingly broke some third-party Office integrations. You can check out Taras's freshly baked Microsoft Weekly roundup to catch up on all the interesting stories this week. This week in science news Image by Steve Johnson via Pexels Catch up on some of the latest science and out-of-this-world updates that arrived throughout the week: The end of the universe: A new Cornell study suggests the universe will not expand forever. Because of the negative dark energy, it could stop expanding and collapse into a "big crunch" in 20 billion years. The impact of traffic: Researchers found that urban traffic pollution, specifically nitrogen oxides and fine particles, quickly alters the atmospheric electric field measurably in urban areas. This indicates that atmospheric electricity could become a valuable tool to monitor urban air quality and activity. The light of life: A study revealed that living organisms emit a faint, invisible glow called ultraweek photon emission. This natural light significantly decreases after death and increases during stress, offering a highly promising new method for noninvasive medical health diagnosis. Mysteries of time: A new study suggests that the direction of time is not fixed in certain quantum systems. Standard equations of energy loss remain time-symmetric, which means laws can theoretically run backward or forward. This week in gaming The latest issue of Pulasthi's Weekend PC Game Deals curates several exciting games on sale this week. Epic Games Store is now hosting Robobeat and Citizen Sleeper as free-to-claim titles this week, which you can add to your library. Latest issue of Xbox Free Play Days features four new games: PGA TOUR 2K25, Two Point Museum, Assetto Corsa, and Dead by Daylight. Meanwhile, Xbox Game Pass got another Call of Duty addition, the latest soccer game from EA, an indie road trip hit from last year, and more. Summer sales have made NVIDIA's gaming service cheaper, and it has added support for seven new titles. That said, here are some more stories from the gaming world: Rockstar gives last-gen GTA V players free upgrades tomorrow Major Xbox layoffs may claim South of Midnight developer Compulsion entirely Steam Next Fest returns with thousands of new demos to try out Forza Horizon 6 gets another hotfix for one of the game's online modes Major Xbox layoffs may claim South of Midnight developer Compulsion entirely From the review corner This week, Steven got his hands on the Creative Sound Blaster AE-X internal PCIe sound card, primarily intended for headphone wearers. In the list of pros, it comes with a high-quality headphone amp, low-latency communication enhancements via ASIO v2.3, offers 256-times the audio quality of CDs via DSD256, and has great build quality. On the other hand, it's a bit on the pricier side, only offers stereo output over speakers, and has no EMI shielding. More price drops! We got you covered with some hot tech deals all week. For some reason, if you missed out on a great discount, here is a summary of some recent deals that are still alive: GEEKOM X16 Pro at GEEKOM - $1,119.67 (17% off) Acer 4K Webcam for PC/Mac with All-Metal Unibody Sculpted - $59.99 (14% off) Samsung 990 PRO SSD 2TB - $369.99 (42% off) Nothing Ear Wireless Earbuds Bluetooth - $73.15 (51% off) PowerColor Reaper AMD Radeon RX 9070 16GB - $579.99 (17% off) To view all of our recent deals, click here. So, these were some of the biggest tech news and other updates from this week. There will be more issues of our 7 Days series in the coming weeks and months, so stay tuned. You can also support Neowin by registering for a free member account or subscribing to extra member benefits, along with an ad-free tier option. Have a great weekend!
    • It certainly is a waste of time clicking it if you're not interested in Windows 11's development. If that were the case for you, you could easily ignore the headline and move on given the headline makes it clear that's what the article is about. Instead, you're contradicting yourself here calling it a waste of time yet clicking on the headline and commenting... If it were a totally different topic being presented than what's stated in the headline, then you'd certainly have a point, 'cause that's totally deceptive and unavoidable if not actually interested. On the contrary, here you can totally avoid it if you're truly not interested.
    • No, it did not work. I did not read the article. I saw the title in my Feedly feed and came to continue putting pressure about such titles on a website I used to love. In fact, based on your reply, it seems you think it's fine to visit click bait title articles to find out what it's about, to waste people's time. That's up to you, mate. I remember when news websites had pride in their content and therefore didn't need to resort to cheap tactics.
  • Recent Achievements

    • Dedicated
      Almohandis earned a badge
      Dedicated
    • Dedicated
      JuvenileDelinquent earned a badge
      Dedicated
    • First Post
      DrWankel earned a badge
      First Post
    • Reacting Well
      DrWankel earned a badge
      Reacting Well
    • Week One Done
      Supreme Spray LV earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      505
    2. 2
      +Edouard
      176
    3. 3
      PsYcHoKiLLa
      84
    4. 4
      Michael Scrip
      76
    5. 5
      Steven P.
      75
  • Tell a friend

    Love Neowin? Tell a friend!