IP Addresses relating to akamai.net

A

Amanda George

I use a network sniffer to monitor traffic on our office
LAN. I have seen a 2 host PCs in my office communicating
w/ some strange IP addresses which don't resolve to DNS
addresses. Sometimes, both hosts communicate with the IP
address or one on the same subnet. When a host has a
conversation w/ these IP addresses, there is often a
large byte transfer on the network. These IP's use Port
80, and on the client-side, the host port varies from TCP
1192 to TCP 1883...any where in that range. The port
changes all the time. I have looked them up in the ARIN
who-is database to find related organization or business-
related info. Link:
http://www.webyield.net/domainquery.html . For example,
I will see a PC communicate with an IP address associated
with unknown.level3.net (63.210.62.86). Others I have
seen are 81.52.250.105, which relates to the RIPE
Coordination Centre when researched on the ARIN database,
and 208.254.0.31 which related to UUNet(which is related
to our data center). After running trace routes and doing
more research, some of these strange IPs relate to
akamai.com and sprintlink. Our company does not use any
Internet services from these companies, nor has any
connection to them. I have run a virus scan and a
spyware scan and made sure all critical security updates
were installed on one of the three PCs and the IP
addresses still appeared after all that. I can see the
IP addresses communicating with a host PC even while a
user is logged off, which leads me to believe the cause
doesn't relate to a user's internet activity. Is there a
way in XP to block this type of activity? How can I get
these IP addresses to disappear from our LAN? Please
advise, thank you.
 
T

Topcat

more than likely you are using Symantec antivirus or related software. on my
computer level3 is the Symantec liveupdate sever.
 
A

Amanda George

Thanks for your response. I have noticed the live update
server notification icon always running on my taskbar.
The client computer is managed by a Symantec server, so
the user cannot run Live Updates manually. Is there a
reason why the Live Update server may be running all the
time?
 
A

Amanda George

Regarding your response to my question about Level3.net
communications.... I saw a client communicating w/
unknown.mzima.net today, which is a company recently
merged with Level 3. Each time a client communicates
with the Live Update server, will the computer
communicate with Level3? Are there any other companies,
the server may communicate with. Please write back,
thank you.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top