unknown process connecting on port 443... ipv6/networkmanager/latest git opensnitch.. systemd-resolved, firefox/firejail? #834
Replies: 6 comments 16 replies
-
Hi @andrewfader , Are you using "proc" or "ebpf" monitor method? (Preferences -> Nodes -> Process Monitor Method) |
Beta Was this translation helpful? Give feedback.
-
I've switched over to ebpf @gustavo-iniguez-goya but I still get an unknown process connecting, what should I do? |
Beta Was this translation helpful? Give feedback.
-
Hmm, actually, I can fix it by unchecking the "debug unknown connections" checkbox it seems. |
Beta Was this translation helpful? Give feedback.
-
mmh, according to the logs , it looks like we're not finding the connection on the ebpf maps. It'd be interesting to dump the maps, but it's a tedious task. Anyway, I think we need a debug log to explicitly say that the connection hasn't been found via ebpf, because it's not clear to me. Could you use There're ebpf exit events in the logs, so maybe there're also exec events prior to the connection. |
Beta Was this translation helpful? Give feedback.
-
@gustavo-iniguez-goya I believe the connections are being created by transmission-cli (bittorrent) |
Beta Was this translation helpful? Give feedback.
-
Running latest opensnitch-git on Arch 6.1.9, and as of the latest update I get a frequent unknown process connecting to ipv6 addresses on port 443... is this something to do with firefox? It seems to happen when I browse around in firefox (and firejail), how can I unmask this unknown process? If I deny it everything works fine but am I just breaking ipv6 loads for something? Using systemd-resolved
Beta Was this translation helpful? Give feedback.
All reactions