primexx Posted July 6, 2008 Share Posted July 6, 2008 One of the machines on my lan currently has ~2k tcp connections, even with a 120s timeout, is this normal??? Link to comment https://www.neowin.net/forum/topic/647430-is-it-normal-to-have-2000-tcp-connections/ Share on other sites More sharing options...
Stephen Veteran Posted July 6, 2008 Veteran Share Posted July 6, 2008 is it running and P2P software? Link to comment https://www.neowin.net/forum/topic/647430-is-it-normal-to-have-2000-tcp-connections/#findComment-589534824 Share on other sites More sharing options...
primexx Posted July 6, 2008 Author Share Posted July 6, 2008 is it running and P2P software? i don't think so, p2p is supposed to be blocked for that comp. the next most number of connections is ~500 right now. Link to comment https://www.neowin.net/forum/topic/647430-is-it-normal-to-have-2000-tcp-connections/#findComment-589534832 Share on other sites More sharing options...
zeta_immersion Posted July 6, 2008 Share Posted July 6, 2008 say hello to something unwanted .. aka. spam/virus/p2p/the funk Link to comment https://www.neowin.net/forum/topic/647430-is-it-normal-to-have-2000-tcp-connections/#findComment-589534836 Share on other sites More sharing options...
primexx Posted July 6, 2008 Author Share Posted July 6, 2008 say hello to something unwanted .. aka. spam/virus/p2p/the funk damn i was afraid of that... anyone know if you could limit connection count by ip or mac on dd-wrt?? Link to comment https://www.neowin.net/forum/topic/647430-is-it-normal-to-have-2000-tcp-connections/#findComment-589534839 Share on other sites More sharing options...
Colin-uk Veteran Posted July 6, 2008 Veteran Share Posted July 6, 2008 type 'netstat -b' in the command prompt and see where and what is making those connections. I would probly do a spyware/virus check too. Link to comment https://www.neowin.net/forum/topic/647430-is-it-normal-to-have-2000-tcp-connections/#findComment-589534840 Share on other sites More sharing options...
primexx Posted July 6, 2008 Author Share Posted July 6, 2008 type 'netstat -b' in the command prompt and see where and what is making those connections. I would probly do a spyware/virus check too. it says illegal command? Link to comment https://www.neowin.net/forum/topic/647430-is-it-normal-to-have-2000-tcp-connections/#findComment-589534857 Share on other sites More sharing options...
tsupersonic Posted July 6, 2008 Share Posted July 6, 2008 Update your antivirus and antispyware etc, then unhook from the internet. Boot into safe mode, then run the antivirus and antispyware. The safe mode part is important 2000 is way too damn much. Using the netstat -b command in cmd prompt, it shows 2 for me, and it's just Opera Link to comment https://www.neowin.net/forum/topic/647430-is-it-normal-to-have-2000-tcp-connections/#findComment-589534860 Share on other sites More sharing options...
primexx Posted July 6, 2008 Author Share Posted July 6, 2008 Update your antivirus and antispyware etc, then unhook from the internet. Boot into safe mode, then run the antivirus and antispyware. The safe mode part is important2000 is way too damn much. Using the netstat -b command in cmd prompt, it shows 2 for me, and it's just Opera oh netstat on the computer! I don't have control/access to it. And i don't really care if it's infected as long as it doesn't bring the rest of the network down...so if there's no way of limiting connections by client i guess i'll have to tell them to check their comp...blah... Link to comment https://www.neowin.net/forum/topic/647430-is-it-normal-to-have-2000-tcp-connections/#findComment-589534864 Share on other sites More sharing options...
5c077 Posted July 6, 2008 Share Posted July 6, 2008 That's crazy, I'd definitely take that computer offline until you remove whatever is causing that. It's more than likely infected to the point it needs a format. Link to comment https://www.neowin.net/forum/topic/647430-is-it-normal-to-have-2000-tcp-connections/#findComment-589534964 Share on other sites More sharing options...
+BudMan MVC Posted July 6, 2008 MVC Share Posted July 6, 2008 i don't really care if it's infected :blink: WTF dude??? Your joking right??? Link to comment https://www.neowin.net/forum/topic/647430-is-it-normal-to-have-2000-tcp-connections/#findComment-589534995 Share on other sites More sharing options...
primexx Posted July 6, 2008 Author Share Posted July 6, 2008 (edited) :blink: WTF dude??? Your joking right??? read the second part: as long as it doesn't take the rest of the lan down. (oh and none of the computers are actually networked together, so i should be safe...correct me if i'm wrong please?) So...any way to limit connections by client??? Edited July 6, 2008 by Primexx Link to comment https://www.neowin.net/forum/topic/647430-is-it-normal-to-have-2000-tcp-connections/#findComment-589535016 Share on other sites More sharing options...
MrKuro Posted July 6, 2008 Share Posted July 6, 2008 i generally have around upwards of 3000 tcp connections, but when running heavy torrent transfers, which is usually 24/7 (maxing my connection bandwidth), however when not doing those activities i might have 20-50 connections going on (web/terminal services traffic) so .. if your not using p2p, you probably have some spyware/virus going on. Link to comment https://www.neowin.net/forum/topic/647430-is-it-normal-to-have-2000-tcp-connections/#findComment-589535022 Share on other sites More sharing options...
primexx Posted July 6, 2008 Author Share Posted July 6, 2008 i generally have around upwards of 3000 tcp connections, but when running heavy torrent transfers, which is usually 24/7 (maxing my connection bandwidth), however when not doing those activities i might have 20-50 connections going on (web/terminal services traffic)so .. if your not using p2p, you probably have some spyware/virus going on. the other possibility, i guess, is that dd-wrt's p2p blocking doesn't actually do what it says, i don't doubt the possibility. Link to comment https://www.neowin.net/forum/topic/647430-is-it-normal-to-have-2000-tcp-connections/#findComment-589535028 Share on other sites More sharing options...
h3xis Posted July 6, 2008 Share Posted July 6, 2008 what version of dd-wrt? if you're running v24 you can see what the connections are. Link to comment https://www.neowin.net/forum/topic/647430-is-it-normal-to-have-2000-tcp-connections/#findComment-589535054 Share on other sites More sharing options...
primexx Posted July 6, 2008 Author Share Posted July 6, 2008 what version of dd-wrt? if you're running v24 you can see what the connections are. i can but i can't make sense of them Link to comment https://www.neowin.net/forum/topic/647430-is-it-normal-to-have-2000-tcp-connections/#findComment-589535083 Share on other sites More sharing options...
h3xis Posted July 6, 2008 Share Posted July 6, 2008 why not? what are the source addresses? are they all different or what? Link to comment https://www.neowin.net/forum/topic/647430-is-it-normal-to-have-2000-tcp-connections/#findComment-589535109 Share on other sites More sharing options...
primexx Posted July 6, 2008 Author Share Posted July 6, 2008 why not? what are the source addresses? are they all different or what? there's no single or even a few recurring IPs Link to comment https://www.neowin.net/forum/topic/647430-is-it-normal-to-have-2000-tcp-connections/#findComment-589535152 Share on other sites More sharing options...
DaTech Posted July 6, 2008 Share Posted July 6, 2008 get a router! IF YOU HAVE INTERNET YOU SHOULD HAVE A ROUTER!!! unless you already got one but it sure don't sound like it! Link to comment https://www.neowin.net/forum/topic/647430-is-it-normal-to-have-2000-tcp-connections/#findComment-589535157 Share on other sites More sharing options...
PermaSt0ne Posted July 6, 2008 Share Posted July 6, 2008 get a router!IF YOU HAVE INTERNET YOU SHOULD HAVE A ROUTER!!! unless you already got one but it sure don't sound like it! .......ummm yea try reading that one more time as for the OP, most torrents and p2p have a way of getting past firewalls and routers. they randomize the ports they go through and can encrypt their traffic. even if you block all the ports except for 80 they can still work i know of no way to guarantee that torrent and p2p traffic won't work. maybe budman knows :huh: Link to comment https://www.neowin.net/forum/topic/647430-is-it-normal-to-have-2000-tcp-connections/#findComment-589535168 Share on other sites More sharing options...
h3xis Posted July 6, 2008 Share Posted July 6, 2008 get a router!IF YOU HAVE INTERNET YOU SHOULD HAVE A ROUTER!!! unless you already got one but it sure don't sound like it! facepalm there's no single or even a few recurring IPs so let me get this straight, one of your machines has ~2000 tcp connections, but hardly any of them (if any) are showing up in the active connections list? Link to comment https://www.neowin.net/forum/topic/647430-is-it-normal-to-have-2000-tcp-connections/#findComment-589535191 Share on other sites More sharing options...
primexx Posted July 6, 2008 Author Share Posted July 6, 2008 facepalmso let me get this straight, one of your machines has ~2000 tcp connections, but hardly any of them (if any) are showing up in the active connections list? oh I see the list, but there's no single IP it's connecting to, and I haven't found a feasible way of analyzing a thousand or so unique IPs from a copy+paste of the list yet. Link to comment https://www.neowin.net/forum/topic/647430-is-it-normal-to-have-2000-tcp-connections/#findComment-589535195 Share on other sites More sharing options...
primexx Posted July 6, 2008 Author Share Posted July 6, 2008 (edited) I have a sample (csv) of the connections, should I post it? Edited July 6, 2008 by Primexx Link to comment https://www.neowin.net/forum/topic/647430-is-it-normal-to-have-2000-tcp-connections/#findComment-589535274 Share on other sites More sharing options...
+shift. MVC Posted July 6, 2008 MVC Share Posted July 6, 2008 get a router!IF YOU HAVE INTERNET YOU SHOULD HAVE A ROUTER!!! unless you already got one but it sure don't sound like it! :rolleyes: He did say he was running DD-WRT. :p Link to comment https://www.neowin.net/forum/topic/647430-is-it-normal-to-have-2000-tcp-connections/#findComment-589535288 Share on other sites More sharing options...
Recommended Posts