TCP Connection - Established

From: John (john_at_somewhere.com)
Date: 01/31/04


Date: Sat, 31 Jan 2004 01:40:17 GMT

I am using W2K Workstation, not joined to a domain, ie. standalone. I
use an ADSL connection to the internet.

I ran netstat -a -n to see the connections that existed and there was a
connection with status "established" that got my attention.

Netstat shows

TCP mynumericIPaddress:1525 207.33.111.82:8195 Established

The interesting thing is that the connection remains even if my Sygate
personal firewall is "blocking all traffic".

I also made a rule to block traffic (in or out) on TCP to remote port
8195 with any packets logged. There were no packets, suggesting this
connection was not generating any traffic.

I downloaded a "whois" utility and searched 207.33.111.82 and the result
was "no such address".

It seems to be something happening inside my machine only, but I thought
netstat only reported external connections.

Can anyone explain?

Thanks

John.



Relevant Pages

  • RE: Windows XP open port 389
    ... Internet Connection Sharing in WIN XP should use NAT (Network Address ... Windows XP open port 389 ... I believe the Internet Locator Service cannot be installed on Windows ... 389 Internet Locator Service TCP ...
    (Focus-Microsoft)
  • ppp interruption
    ... Problem with maintaining the internet connection: on startup I do: ... Routing tables ... following netstat -rn printout: ...
    (freebsd-questions)
  • Re: ppp interruption
    ... Problem with maintaining the internet connection: on startup I do: ... Routing tables ... I get the following netstat -rn printout: ...
    (freebsd-questions)
  • Re: Sendmail says No, But netstat says Yes
    ... connection from ever taking place and thus never be reported by netstat. ... When I blocked the machines in question, ... Why didn't tcp wrapping work? ...
    (comp.mail.sendmail)
  • Re: Using putty to debug ssh through a firewall
    ... If you do a "netstat -n" and pick out the TCP ... connection in question, can you see the value of the "Send-Q" on ... ssh client nor the Wireshark readout. ...
    (comp.security.ssh)