Date: Mon, 10 May 2004 00:31:43 -0500 (CDT) From: Chris Dillon <cdillon@wolves.k12.mo.us> To: TSaplin Mikhail <tsmm@list.ru> Cc: freebsd-hackers@freebsd.org Subject: Re: GATEKEEPER.MCAST.NET again (unexpected traffic) Message-ID: <20040510001226.T67823@duey.wolves.k12.mo.us> In-Reply-To: <200405091922.36624.tsmm@list.ru> References: <200405091922.36624.tsmm@list.ru>
next in thread | previous in thread | raw e-mail | index | archive | help
On Sun, 9 May 2004, TSaplin Mikhail wrote: > Recently I wrote, that I have litle traffic to GATEKEEPER.MCAST.NET, > (tcpdump show this: > 20:32:41.496039 129dial.supernet.kz.52075 > GATEKEEPER.MCAST.NET.1718: udp 31 > ) > > David Malone <dwmalone@maths.tcd.ie> on my question wrote: > >Does sockstat show which process is using port 52075? > No, sockstat show nothing about this. > > I've installed new system due express installation - but packets is steel > going. > > Maybe this is going on your 5.1 system, and is this right? Those are multicast UDP packets being sent by an H.323 endpoint application trying to find a local H.323 gatekeeper. Since they are multicast, they will stay within your LAN unless you have explicitly configured a router or tunnel to carry them out of it. Totally harmless, unless you really don't want any H.323-enabled applications installed and running. Use sockstat to look for anything listening on the 224.0.1.41 (gatekeeper.mcast.net) address. -- Chris Dillon - cdillon(at)wolves.k12.mo.us FreeBSD: The fastest, most open, and most stable OS on the planet - Available for IA32, IA64, AMD64, PC98, Alpha, and UltraSPARC architectures - PowerPC, ARM, MIPS, and S/390 under development - http://www.freebsd.org Q: Because it reverses the logical flow of conversation. A: Why is putting a reply at the top of the message frowned upon?
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20040510001226.T67823>