Hello,
I have a test exchange server at home, and I ran a netstat -an on it to see what ports were being accessed, etc. I was surprised to see so many established connections. Does this look normal for an exchange 2000 server? I have none to compare this to, so it looks very unusual. This is on a home network with no firewall but behind a router using internal IP addressing...
Active Connections
Proto Local Address Foreign Address State
TCP 0.0.0.0:21 0.0.0.0:0 LISTENING
TCP 0.0.0.0:25 0.0.0.0:0 LISTENING
TCP 0.0.0.0:42 0.0.0.0:0 LISTENING
TCP 0.0.0.0:53 0.0.0.0:0 LISTENING
TCP 0.0.0.0:80 0.0.0.0:0 LISTENING
TCP 0.0.0.0:88 0.0.0.0:0 LISTENING
TCP 0.0.0.0:110 0.0.0.0:0 LISTENING
TCP 0.0.0.0:119 0.0.0.0:0 LISTENING
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING
TCP 0.0.0.0:143 0.0.0.0:0 LISTENING
TCP 0.0.0.0:389 0.0.0.0:0 LISTENING
TCP 0.0.0.0:443 0.0.0.0:0 LISTENING
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING
TCP 0.0.0.0:464 0.0.0.0:0 LISTENING
TCP 0.0.0.0:563 0.0.0.0:0 LISTENING
TCP 0.0.0.0:593 0.0.0.0:0 LISTENING
TCP 0.0.0.0:636 0.0.0.0:0 LISTENING
TCP 0.0.0.0:691 0.0.0.0:0 LISTENING
TCP 0.0.0.0:993 0.0.0.0:0 LISTENING
TCP 0.0.0.0:995 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1027 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1029 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1036 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1046 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1048 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1049 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1050 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1051 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1080 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1083 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1088 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1090 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1101 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1106 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1112 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1114 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1116 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1118 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1120 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1130 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1131 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1132 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1133 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1134 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1137 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1141 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1142 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1143 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1144 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1145 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1146 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1147 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1148 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1162 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1163 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1183 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1184 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1185 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1186 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1187 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1188 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1189 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1190 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1191 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1192 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1193 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1194 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1195 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1196 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1197 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1198 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1199 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1200 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1201 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1204 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1208 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1209 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1210 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1211 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1212 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1213 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1214 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1215 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1216 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1217 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1218 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1231 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1232 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1233 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1234 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1235 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1236 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1237 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1238 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1239 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1240 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1241 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1242 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1243 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1244 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1245 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1246 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1248 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1256 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1257 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1258 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1259 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1260 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1261 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1262 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1263 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1264 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1265 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1266 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1267 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1268 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1269 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1270 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1271 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1272 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1274 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1298 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1310 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1377 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1378 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1379 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1380 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1381 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1384 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1385 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1386 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1387 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1388 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1389 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1390 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1391 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1392 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1393 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1472 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1525 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1533 0.0.0.0:0 LISTENING
TCP 0.0.0.0:3268 0.0.0.0:0 LISTENING
TCP 0.0.0.0:3269 0.0.0.0:0 LISTENING
TCP 0.0.0.0:3372 0.0.0.0:0 LISTENING
TCP 0.0.0.0:6101 0.0.0.0:0 LISTENING
TCP 0.0.0.0:9988 0.0.0.0:0 LISTENING
TCP 127.0.0.1:389 127.0.0.1:1048 ESTABLISHED
TCP 127.0.0.1:389 127.0.0.1:1049 ESTABLISHED
TCP 127.0.0.1:389 127.0.0.1:1051 ESTABLISHED
TCP 127.0.0.1:389 127.0.0.1:1088 ESTABLISHED
TCP 127.0.0.1:1046 127.0.0.1:389 CLOSE_WAIT
TCP 127.0.0.1:1048 127.0.0.1:389 ESTABLISHED
TCP 127.0.0.1:1049 127.0.0.1:389 ESTABLISHED
TCP 127.0.0.1:1051 127.0.0.1:389 ESTABLISHED
TCP 127.0.0.1:1088 127.0.0.1:389 ESTABLISHED
TCP 192.168.0.3:139 0.0.0.0:0 LISTENING
TCP 192.168.0.3:139 192.168.0.199:3268 ESTABLISHED
TCP 192.168.0.3:389 192.168.0.3:1114 ESTABLISHED
TCP 192.168.0.3:389 192.168.0.3:1130 ESTABLISHED
TCP 192.168.0.3:389 192.168.0.3:1134 ESTABLISHED
TCP 192.168.0.3:389 192.168.0.3:1162 ESTABLISHED
TCP 192.168.0.3:389 192.168.0.3:1187 ESTABLISHED
TCP 192.168.0.3:389 192.168.0.3:1198 ESTABLISHED
TCP 192.168.0.3:389 192.168.0.3:1200 ESTABLISHED
TCP 192.168.0.3:389 192.168.0.3:1208 ESTABLISHED
TCP 192.168.0.3:389 192.168.0.3:1209 ESTABLISHED
TCP 192.168.0.3:389 192.168.0.3:1210 ESTABLISHED
TCP 192.168.0.3:389 192.168.0.3:1211 ESTABLISHED
TCP 192.168.0.3:389 192.168.0.3:1212 ESTABLISHED
TCP 192.168.0.3:389 192.168.0.3:1231 ESTABLISHED
TCP 192.168.0.3:389 192.168.0.3:1235 ESTABLISHED
TCP 192.168.0.3:389 192.168.0.3:1256 ESTABLISHED
TCP 192.168.0.3:389 192.168.0.3:1260 ESTABLISHED
TCP 192.168.0.3:389 192.168.0.3:1271 ESTABLISHED
TCP 192.168.0.3:389 192.168.0.3:1377 ESTABLISHED
TCP 192.168.0.3:389 192.168.0.3:1381 ESTABLISHED
TCP 192.168.0.3:389 192.168.0.3:1525 ESTABLISHED
TCP 192.168.0.3:445 192.168.0.3:1533 ESTABLISHED
TCP 192.168.0.3:691 192.168.0.3:1197 ESTABLISHED
TCP 192.168.0.3:691 192.168.0.3:1245 ESTABLISHED
TCP 192.168.0.3:691 192.168.0.3:1270 ESTABLISHED
TCP 192.168.0.3:691 192.168.0.3:1393 ESTABLISHED
TCP 192.168.0.3:1027 192.168.0.3:1116 ESTABLISHED
TCP 192.168.0.3:1027 192.168.0.3:1310 ESTABLISHED
TCP 192.168.0.3:1027 192.168.0.3:1472 ESTABLISHED
TCP 192.168.0.3:1114 192.168.0.3:389 ESTABLISHED
TCP 192.168.0.3:1116 192.168.0.3:1027 ESTABLISHED
TCP 192.168.0.3:1130 192.168.0.3:389 ESTABLISHED
TCP 192.168.0.3:1131 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1132 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1133 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1134 192.168.0.3:389 ESTABLISHED
TCP 192.168.0.3:1137 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1141 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1142 192.168.0.3:3268 ESTABLISHED
TCP 192.168.0.3:1143 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1144 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1145 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1146 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1147 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1148 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1162 192.168.0.3:389 ESTABLISHED
TCP 192.168.0.3:1163 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1183 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1184 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1185 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1186 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1187 192.168.0.3:389 ESTABLISHED
TCP 192.168.0.3:1188 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1189 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1190 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1191 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1192 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1193 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1194 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1195 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1196 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1197 192.168.0.3:691 ESTABLISHED
TCP 192.168.0.3:1198 192.168.0.3:389 ESTABLISHED
TCP 192.168.0.3:1199 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1200 192.168.0.3:389 ESTABLISHED
TCP 192.168.0.3:1201 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1204 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1208 192.168.0.3:389 ESTABLISHED
TCP 192.168.0.3:1209 192.168.0.3:389 ESTABLISHED
TCP 192.168.0.3:1210 192.168.0.3:389 ESTABLISHED
TCP 192.168.0.3:1211 192.168.0.3:389 ESTABLISHED
TCP 192.168.0.3:1212 192.168.0.3:389 ESTABLISHED
TCP 192.168.0.3:1213 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1214 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1215 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1216 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1217 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1218 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1231 192.168.0.3:389 ESTABLISHED
TCP 192.168.0.3:1232 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1233 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1234 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1235 192.168.0.3:389 ESTABLISHED
TCP 192.168.0.3:1236 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1237 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1238 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1239 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1240 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1241 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1242 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1243 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1244 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1245 192.168.0.3:691 ESTABLISHED
TCP 192.168.0.3:1256 192.168.0.3:389 ESTABLISHED
TCP 192.168.0.3:1257 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1258 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1259 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1260 192.168.0.3:389 ESTABLISHED
TCP 192.168.0.3:1261 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1262 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1263 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1264 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1265 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1266 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1267 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1268 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1269 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1270 192.168.0.3:691 ESTABLISHED
TCP 192.168.0.3:1271 192.168.0.3:389 ESTABLISHED
TCP 192.168.0.3:1310 192.168.0.3:1027 ESTABLISHED
TCP 192.168.0.3:1377 192.168.0.3:389 ESTABLISHED
TCP 192.168.0.3:1378 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1379 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1380 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1381 192.168.0.3:389 ESTABLISHED
TCP 192.168.0.3:1384 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1385 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1386 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1387 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1388 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1389 192.168.0.3:389 CLOSE_WAIT
TCP 192.168.0.3:1390 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1391 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1392 192.168.0.3:3268 CLOSE_WAIT
TCP 192.168.0.3:1393 192.168.0.3:691 ESTABLISHED
TCP 192.168.0.3:1472 192.168.0.3:1027 ESTABLISHED
TCP 192.168.0.3:1525 192.168.0.3:389 ESTABLISHED
TCP 192.168.0.3:1533 192.168.0.3:445 ESTABLISHED
TCP 192.168.0.3:3268 192.168.0.3:1142 ESTABLISHED
...
Sorry for the long post, but why does it have so many connections to itself?
Thanks,
Finnian
Is this normal for a win2k exchange server?
It's normal for a vanilla install of Windows 2000 running Exchange 2000. It's unfortunate that Exchange 2000 forces you to install IIS (Inherently Insecure Server) on the system. If your not going to use all the services you have running, you may want to disable some services:
Port 21 is listening, are you running an FTP server?
Port 119 is listening, are you running a Newsgroup server?
Port 42 is listening, are you using WINS?
Port 443 is listening, do you need secure HTTP traffic?
Port 80 is listening, do you need OWA or HTTP services?
Port 143 is listening, do you need IMAP support?
Port 110 is listening, do you need POP3 support?
the other ones like 135,445,464,593 are normal and should be open.
Ports like 636,993,995 are the secure equivilents of LDAP, IMAP and POP3 respectively.
The other ports higher than 1024, off the top of my head I'm not sure why they are open. Here's a place to look to see what the function of the port is. There are other sites that have this information, this happen to be the one first in my favs.
http://www.networksorcery.com/enp/proto ... s00000.htm
As far as the listing like this one:
TCP 192.168.0.3:389 192.168.0.3:1114 ESTABLISHED
That's telling you that LDAP is communicating with another machine. You can see a ton of LDAP communications in your output. This is normal for Windows 2000.
The MS routing port 691 is cool.
It seems to me that this machine is not only a Exchange server but also a domain controller. This would explain port 53, 42 (Running WINS and DNS is odd but beyond the scope of your question) and the amount of traffic on 389 and 445. That's cool for a test or home network, but avoid running your messaging system on a domain controller in a corporate environment.
I hope this helps.
Port 21 is listening, are you running an FTP server?
Port 119 is listening, are you running a Newsgroup server?
Port 42 is listening, are you using WINS?
Port 443 is listening, do you need secure HTTP traffic?
Port 80 is listening, do you need OWA or HTTP services?
Port 143 is listening, do you need IMAP support?
Port 110 is listening, do you need POP3 support?
the other ones like 135,445,464,593 are normal and should be open.
Ports like 636,993,995 are the secure equivilents of LDAP, IMAP and POP3 respectively.
The other ports higher than 1024, off the top of my head I'm not sure why they are open. Here's a place to look to see what the function of the port is. There are other sites that have this information, this happen to be the one first in my favs.
http://www.networksorcery.com/enp/proto ... s00000.htm
As far as the listing like this one:
TCP 192.168.0.3:389 192.168.0.3:1114 ESTABLISHED
That's telling you that LDAP is communicating with another machine. You can see a ton of LDAP communications in your output. This is normal for Windows 2000.
The MS routing port 691 is cool.
It seems to me that this machine is not only a Exchange server but also a domain controller. This would explain port 53, 42 (Running WINS and DNS is odd but beyond the scope of your question) and the amount of traffic on 389 and 445. That's cool for a test or home network, but avoid running your messaging system on a domain controller in a corporate environment.
I hope this helps.
-
fcorneli
Thanks
Hello,
Woot! Thanks, someone that knows enough to teach me something. hehe Thanks!! Yes, it helps a ton. I've been looking for a place that would explain ports used, etc. for a while. Yes, it is just a test server to practice for my exchange 2000 exam (my last needed for MCSE). I really appreciate you taking the time to help me out!
/cheer
EDIT: I thought exchange 2000 had to be installed on a DC though?
Thanks,
Finnian
Woot! Thanks, someone that knows enough to teach me something. hehe Thanks!! Yes, it helps a ton. I've been looking for a place that would explain ports used, etc. for a while. Yes, it is just a test server to practice for my exchange 2000 exam (my last needed for MCSE). I really appreciate you taking the time to help me out!
/cheer
EDIT: I thought exchange 2000 had to be installed on a DC though?
Thanks,
Finnian