Q: Did all/most of the other connections in time wait also use port 568?
Q: Did they come from the same remote host?
Q: Does "netstat" show you which process is *listening* on port 568?
1. You can use "lsof" to see which processes are using which TCP ports
2. You can use wireshark to take a trace of what's happening.
Here's one other link that might help: