Avast AvastSvc.exe Lots of UDP 53 and 443 sessions over WAN

Why does Avast connect to almost 700 different sessions during a new network connection to the internet over UDP ports 53 and 443? Also, they are all over the world… Turkey, China, Russia, Poland… How do I stop or limit this behavior? It seriously opens about 700 sessions on connection to IPs across the globe.

178.18.201.98
ist84-001.ff.avast.com - Turkey

93.93.67.140
mad81-002.ff.avast.com

93.93.68.18
mad81-003.ff.avast.com

62.210.203.107
par06.ff.avast.com

195.154.167.241
par05.ff.avast.com

193.218.154.52
waw81-002.ff.avast.com - poland

95.213.183.138
led81-005.ff.avast.com

195.78.228.148
mad81-004.ff.avast.com - Spain

Is Avast also responsible for the many connections to RIPE ?

168.1.69.109
RIPE Network Coordination Centre
P.O. Box 10096
Amsterdam, 1001EB
NETHERLANDS

SoftLayer Technologies
158.85.77.190

SoftLayer - Hong Kong
119.81.145.166
AVAST SOFTWARE S.R.O.
NETBLK-SOFTLAYER-APNIC-CUST-OR20-AP
CZECH REPUBLIC

softlayer.com - Japan
161.202.108.196
RaidCall (HK) Limited
NETBLK-SOFTLAYER-RIPE-CUST-SL10450-RIPE
CHINA

etc

The number of connections / sessions is ridiculous. I got tired of looking them up.

Thanks!

Hi,
UDP port 53 is used for DNS - name resolution. Avast may query names for several of its services, and since we run many data centers all over the world, it may be more than just a few. If we are talking about UDP and port 53, these are most probably not connections/sessions, but just DNS requests.

Which program do you use to display these sessions?

Thanks.
lukas

Check these topics:

https://forum.avast.com/index.php?topic=161952
https://forum.avast.com/index.php?topic=173791

Well that is going to be a problem for anyone doing Geography based firewall rules. You can’t use Avast if you only connect to the United States. That’s what I’ve seen here. That’s not very inclusive.

I can’t even view my account because Avast is trying to go to the Netherlands and Czech Republic for 5.45.62.70:443. You need to make sure people with Geo blocking at their main firewall can still run Avast within their own country.

Also, I’ve had to disable your “Secure DNS” as Avast stopped connecting to Adobe.com earlier today… probably because I’m going outside the United States YET AGAIN to get my DNS. That’s not very safe in my opinion. I know they are your servers, but you should have servers based wherever your customer’s are located handling the local traffic, not overseas.

FYI - Firewalls now do Geo based blocking. I am using a Fortinet firewall. I am only allowing United States based IP’s etc. I had to create a special rule just to access your forum. You should strongly consider giving customer’s the option to access locally region based servers only.

Please let me know how I configure Avast to stay in the United States IP / DNS / Range and still access Avast “Secure DNS” / “Account” etc.

Also, please let me know all of the Avast FQDN names and IP ranges for my FORTINET firewall rules so I can update avast, use the secure dns and use Avast in general.

Thanks!

UPDATE: “SecDns.csv” has 183 entries. I need all the FQDN’s for avast and all the IP’s or IP ranges please.

UPDATE 2: adding my.avast.com, ipm-provider.ff.avast.com, static.avast.com but need 100% please.

UPDATE 3: Still no luck accessing www.adobe.com with “Secure DNS” enabled… please advise FQDN names or IP ranges and subnets please.

FYI - This message was from Avast Support after asking for United States ONLY ip’s for Avast:

“Our IP range is 91.213.40 - 48.0 - 255. I hope this helps. Please let me know if I can be any further assistance.”

So, I believe they were saying IP’s like 91.213.40.1 were in that range… which resolves to Hungary (Outside U.S.)

http://ipaddress.is/91.213.40.1

Anyone know of IP’s for Avast within U.S. ONLY?

FYI - I am using a Fortinet Firewall and I go to the main console and click “Sessions” There I can see all the Avast connections all over the world… although sadly, that’s NOT really what I want happening…

Verified the recommended Avast IP List with Avast Tech Support… but this doesn’t help really, a ton of these are outside the U.S.

91.213.40.0/255
91.213.41.0/255
91.213.42.0/255
91.213.43.0/255
91.213.44.0/255
91.213.45.0/255
91.213.46.0/255
91.213.47.0/255
91.213.48.0/255


yes, exactly. That’s the right list.


Best regards,

Jevhenij Zacharčenko

AVAST Software s.r.o.
Budejovická 1518/13A
140 00 Prague, Czech Republic

Yeah, this isn’t that good, you can’t have Avast and only connect to United States servers. So much for Geo Blocking on Fortinet.

I highly doubt you can do that for any AV. Remember this is no longer a one country market.
We live in a global market. Avast is headquartered in Prague in the Czech republic.

Yeah, and if they were all over the world in a “global market” that means you’d have servers in each country you could point to. People are going to start Geo Blocking. I suggest you get used to that. You can’t have INSIDE > Any. It’s just too unsafe.

You’re entitled to your opinion. :slight_smile: