cancel
Showing results for 
Search instead for 
Did you mean: 

BESERVER.EXE maintaining connection to external IP

smholden
Level 3
Hello all,

Using the Sysinternals tool TCPView, I noticed something curious on my BE 12.5 media server.  BESERVER.EXE is maintaining a constant connection to 204.0.5.18 over port 80.  A whois lookup shows it belongs to NTT America. LiveUpdate connects to an IP managed by the same company, so I have no doubt it is a legitimate address.

Anybody know what this "heartbeat" is for?  I closed the connection and it re-established a few minutes later.

Thanks in advance!
4 REPLIES 4

smholden
Level 3
Bump.  :)

Philip_D
Level 5
Indeed, i think this deserves a bump.  The only legitimate uses Symantec has to call home is for license verification.  I mean, what else is there?

smholden
Level 3
BESERVER.EXE is now connected to a different IP, 64.206.68.184 over port 80.  I ran Live Update and it contacted the same IP.  Curious...

Ben_L_
Level 6
Employee
I'll have to double check with one of my engineers but I'm about 90% sure that's the connection for Symantec Threatcon level. The Threatcon level can be used to automatically kick off a backup if it reaches a specific level.