net connections

From: McCracken, Denise (Denise.McCracken@misyshealthcare.com)
Date: Mon Sep 15 2003 - 16:09:16 EDT


        Can anyone tell me what these connections might be? They seem to
appear every time this local machine (I'll call it myhost) is accessed over
the network from any other machine, but they're always connected to one
particular in-house machine, which I will call "thathost".

        When a connection to "myhost" is made, these jobs start showing up,
and they gradually go into TIME_WAIT and disappear after the connection is
broken (3 minutes or so). AFAIK, there is no service on this machine that
is supposed to be talking to "thathost", so why does am I getting
connections to it?

OSF1 noclue@AFU:/ # netstat -a
Active Internet connections (including servers)
Proto Recv-Q Send-Q Local Address Foreign Address
(state)
tcp 0 0 myhost.1717 thathost.some.domain
TIME_WAIT
tcp 0 0 myhost.1718 thathost.some.domain
TIME_WAIT
tcp 0 0 myhost.1719 thathost.some.domain
TIME_WAIT
tcp 0 0 myhost.1720 thathost.some.domain
TIME_WAIT
tcp 0 0 myhost.1721 thathost.some.domain
TIME_WAIT

The rest of the network services:

tcp 0 0 *.smtp *.*
LISTEN
tcp 0 0 *.596 *.*
LISTEN
tcp 0 0 *.6000 *.*
LISTEN
tcp 0 0 *.316 *.*
LISTEN
tcp 0 0 *.evm *.*
LISTEN
tcp 0 0 *.1057 *.*
LISTEN
tcp 0 0 *.1972 *.*
LISTEN
tcp 0 0 *.4001 *.*
LISTEN
tcp 0 0 *.49401 *.*
LISTEN
tcp 0 0 *.49400 *.*
LISTEN
tcp 0 0 *.sq-names *.*
LISTEN
tcp 0 0 *.1026 *.*
LISTEN
tcp 0 0 *.printer *.*
LISTEN
tcp 0 0 *.2301 *.*
LISTEN
tcp 0 0 *.dnacml *.*
LISTEN
tcp 0 0 *.initlsms *.*
LISTEN
tcp 0 0 *.imap *.*
LISTEN
tcp 0 0 *.pop3 *.*
LISTEN
tcp 0 0 *.1024 *.*
LISTEN
tcp 0 0 *.dtspc *.*
LISTEN
tcp 0 0 *.suitjd *.*
LISTEN
tcp 0 0 *.cfgmgr *.*
LISTEN
tcp 0 0 *.kdebug *.*
LISTEN
tcp 0 0 *.exec *.*
LISTEN
tcp 0 0 *.login *.*
LISTEN
tcp 0 0 *.shell *.*
LISTEN
tcp 0 0 *.telnet *.*
LISTEN
tcp 0 0 *.ftp *.*
LISTEN
tcp 0 0 *.111 *.*
LISTEN
udp 0 0 *.1025 *.*
udp 0 0 *.1027 *.*
udp 0 0 *.1028 *.*
udp 0 0 *.time *.*
udp 0 0 *.sq-names *.*
udp 0 0 *.111 *.*
udp 0 0 *.snmp *.*
udp 0 0 *.177 *.*
udp 0 0 *.biff *.*
udp 0 0 *.syslog *.*
udp 0 0 *.ntalk *.*
udp 0 0 noclue.binlogd *.*

        Any ideas? See anything there that shouldn't be?

Thanks

-d



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:49:35 EDT