Network manager try to establish connnection to weird ip

Good morning.
I today configured external firewall and detected some blocked attempts. After i started investigation i found exact process which create traffic to weird public ip and port 80. Such connection attempts try to establish over all physical interfaces on computer.

This is netstat statistics :


tcp        0      1 172.27.0.2:53904        116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 172.27.0.2:53904        116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 172.27.0.2:53904        116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 172.27.0.2:53904        116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 172.27.0.2:53904        116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 172.27.0.2:53904        116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 172.27.0.2:53904        116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 172.27.0.2:53904        116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 172.27.0.2:53904        116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 172.27.0.2:53904        116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 172.27.0.2:53904        116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 172.27.0.2:53904        116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 10.111.111.32:54696     116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 10.111.111.32:54696     116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 10.111.111.130:48922    116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 10.111.111.32:54696     116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 10.111.111.130:48922    116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 192.168.43.9:58998      116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 192.168.43.9:58998      116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 192.168.43.9:58998      116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 192.168.43.9:58998      116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 192.168.43.9:58998      116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 192.168.43.9:58998      116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 192.168.43.9:58998      116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 192.168.43.9:58998      116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 192.168.43.9:58998      116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 192.168.43.9:58998      116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 192.168.43.9:58998      116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 192.168.43.9:58998      116.203.91.91:80        SYN_SENT    795/NetworkManager  
tcp        0      1 192.168.43.9:58998      116.203.91.91:80        SYN_SENT    795/NetworkManager

795 ? Ssl 14:40 /usr/bin/NetworkManager --no-daemon

Do somebody know what it can be ? I not see anywhere in configuration of network manager such ip address. Something hardcoded ?

It is the connectivity check. You can disable it if you want or use your own server.

https://wiki.archlinux.org/title/NetworkManager#Checking_connectivity

This topic was automatically closed 2 days after the last reply. New replies are no longer allowed.