Re: TCP Connections, Bluesocket, and Mac OS X
- From: "bubbaswan" <evan.sherwood@xxxxxxxxx>
- Date: 7 Mar 2006 19:07:09 -0800
"too many open network connections" determined exactly how?
I'm not exactly sure, but probably just by concurrent open sessions.
That's historical, not current.
I thought it might be, since it didn't decrease when programs accessing
the internet were quit. I fooled around with netstat some and I think
I got a more accurate (and reasonable count) for my particular machine:
blank:~ evan$ netstat
Active Internet connections
Proto Recv-Q Send-Q Local Address Foreign Address
(state)
tcp4 0 0 blank.57036 mailsv02.colgate.imap
ESTABLISHED
tcp4 0 0 blank.56970 mailsv02.colgate.imap
ESTABLISHED
tcp4 0 0 blank.56965 mailsv02.colgate.imap
ESTABLISHED
tcp4 0 0 localhost.56958 localhost.ipp
CLOSE_WAIT
tcp4 0 0 localhost.56957 localhost.ipp
CLOSE_WAIT
tcp4 0 0 localhost.netinfo-loca localhost.976
ESTABLISHED
tcp4 0 0 localhost.976 localhost.netinfo-loca
ESTABLISHED
The rest were UDP connections that had no associated state and local
UNIX domain socket streams. However, even Mac's with these low open
connection counts are still getting quarentined because of the
aforementioned Bluesocket policy.
You can turn this feature off in Bluesocket (administrative web GUI -
General --> IDS). But really - do you want this number of connections
going thru your wireless network?
We don't want to turn off this feature, precisely because of the reason
you mentioned next (about worms and all), and we really don't want this
many connections going through the network. However, we also don't
want OSX machines that apparently don't have a huge number of open
connections getting quarentined because Bluesocket thinks they have
that many open connections. Could it be that a particular legitimate
app, when launching, or performing some other task, opens up a large
number of connections at a particular point, which might cause the
Bluesocket to raise red flags? For instance, with web browsing - if I
were to browse several different sites at once through tabbed browsing,
or something similar? I'm just trying to figure out why Bluesocket
thinks that these Mac's are so busy on the network when they really
don't appear to be.
There isn't a sanctioned big-eight newsgroup for OSX, but you are posting
from googlegroups - why not search there for such a group.
I've looked in other newsgroups to no avail - since the issue seems to
be more on the end of Bluesocket rather than OSX, I thought it best to
post here.
.
- Follow-Ups:
- Re: TCP Connections, Bluesocket, and Mac OS X
- From: Moe Trin
- Re: TCP Connections, Bluesocket, and Mac OS X
- References:
- TCP Connections, Bluesocket, and Mac OS X
- From: evan . sherwood
- Re: TCP Connections, Bluesocket, and Mac OS X
- From: Moe Trin
- TCP Connections, Bluesocket, and Mac OS X
- Prev by Date: Re: Which antenna to upgrade?
- Next by Date: Re: Which antenna to upgrade?
- Previous by thread: Re: TCP Connections, Bluesocket, and Mac OS X
- Next by thread: Re: TCP Connections, Bluesocket, and Mac OS X
- Index(es):
Relevant Pages
|