Solved

Why am I getting all these TCP connections from places I don't know.

Posted on 2014-02-28
12
388 Views
Last Modified: 2014-03-11
My computer is running slow and I think it is because of TCP connections coming in to my computer.

See image below.  What can I do to stop this kind of stuff?

TCP Port Connections reported by "netstat -no"
Thanks for your help.
0
Comment
Question by:LessonsLearned
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 2
  • +3
12 Comments
 
LVL 83

Assisted Solution

by:Dave Baldwin
Dave Baldwin earned 100 total points
ID: 39896544
Those are IP addresses that you are connecting to with either your web browser or maybe some media program.  What programs did you have open when you did this scan?

74.125.0.0 - 74.125.255.255 is Google.
23.72.0.0 - 23.79.255.255 is the AKAMAI content delivery network.
207.200.0.0 - 207.200.63.255 is OnRamp but I don't know what they do.
66.63.128.0 - 66.63.128.255 is Nethere and I don't know what they do either.

You can look up all the others too.  There is nothing wrong with having all those connections.  They can simply be a result of using your web browser.
0
 
LVL 37

Assisted Solution

by:bbao
bbao earned 275 total points
ID: 39896546
Download and run TCPVIEW from Microsoft to check which program or process is causing most connections.

http://technet.microsoft.com/en-us/sysinternals/bb897437.aspx
0
 
LVL 95

Expert Comment

by:John Hurst
ID: 39896548
Some of the IP addresses are Onramp (Your ISP maybe) and Akamai (content supplier). It looks (in a brief look) like stuff you asked for.

Do you keep IE open with lots of open tabs?
0
NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

 
LVL 7

Expert Comment

by:Sivaraj E
ID: 39896715
You can install WireShark a free open source network traffic and port monitoring tool to analyze, Its a real time analyzer.

http://www.wireshark.org/download.html

Regards, Shiva
0
 
LVL 37

Accepted Solution

by:
bbao earned 275 total points
ID: 39896830
even if you use NETSTAT only, you may use -o option to display the owning process ID associated with each connection, therefore you can trace back to the process name per ID using Windows Task Manager.
0
 
LVL 62

Expert Comment

by:gheist
ID: 39897860
Your netstat looks like you use IE to browse the web... Problem is somewhere else.
0
 

Author Comment

by:LessonsLearned
ID: 39900594
Oh, okay.  So this is normal.  I do use IE and Firefox to browse the web, but I close them when I am finished.   Correct me if I am wrong, but when I close the browsers, shouldn't the tcp connections close as well?
0
 
LVL 62

Expert Comment

by:gheist
ID: 39900652
TCP stack is expected to keep lingering (kind of not completely closed) connections open for a while after protocol closed locally
0
 
LVL 37

Expert Comment

by:bbao
ID: 39900676
> when I close the browsers, shouldn't the tcp connections close as well?

basically, YES.

technically, you can't see the connections disappear instantly as it may take a while waiting for timeout. Eventually, all connections established by IE will be closed once IE is terminated.
0
 
LVL 62

Assisted Solution

by:gheist
gheist earned 125 total points
ID: 39901215
No, time_wait connections wait for predefined time so other end has chance to close correctly. They are no more sockets held by a process.
0
 

Author Closing Comment

by:LessonsLearned
ID: 39921092
Thank you very much.  I now have a better understanding of how this works.
0
 
LVL 37

Expert Comment

by:bbao
ID: 39922338
> No, time_wait connections wait for
predefined time so other end has
chance to close correctly. They are no
more sockets held by a process.

thanks for correcting me.
0

Featured Post

Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When it comes to security, there are always trade-offs between security and convenience/ease of administration. This article examines some of the main pros and cons of using key authentication vs password authentication for hosting an SFTP server.
During and after that shift to cloud, one area that still poses a struggle for many organizations is what to do with their department file shares.
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…

690 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question