Solved

TCPView questions

Posted on 2011-03-07
1
329 Views
Last Modified: 2012-05-11
Hi

I have an application server, Server1, running on Windows 2008 Server. I have clients from many subnets connecting to it, some are on the same LAN, some are connecting across the WAN.

We often have connectivity issues so I was looking for a program/function that told me whether the server had actually recvd the connection from the client and what state it was in. I figured on Netstat but then came across TCPView.

I had some questions I was hoping someone could assist me with:

1. If I had a connection from a client at 192.168.1.246, is there a way to actually filter for this, or do I need to sort by IP address (Remote Address).

2. If I had a suspect connection from 192.168.2.123 and wanted to close this, what's the best way to do this?

3. I see there are connection states of:

Listening
Established
Close_Wait
Last_ACK

etc.

Does anyone have a handy link to explain what these mean?
0
Comment
Question by:chuckp2010
1 Comment
 
LVL 57

Accepted Solution

by:
giltjr earned 500 total points
ID: 35060775
1) TCPView has no filtering capabilities.



2) That I am aware of Windows does not have a way to terminate a specific active TCP connection.  I'm not sure, but I don't think *nix does either.

3) Although for the NETSTAT command it the same states: http://support.microsoft.com/kb/137984

You may want to look into Wireshark (http://www.wireshark.org).  This allows you to capture traffic and see what they are doing.  This allows you to filter on specific IP address (and TCP or UDP ports along with a lot of other filtering capabilities).
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

A procedure for exporting installed hotfix details of remote computers using powershell
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

914 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now