I installed Ultra VPN, a free VPN which makes an SSL connection to VPN servers. I have noticed unusual changes in the Active Connections window of Comodo Firewall. Under “Source” I see an IP address of IANA and under “Destination” I see several different IPs, some of which are RIPE, some of which are telecommunications companies. Why would an IP address that is not the IP address of my PC be listed under"Source"? And why are all of these connections occuring under the “Protocol” of “ashWebSv” (this is a component of Avast Antivirus) - shouldn’t all connections be going through the VPN?
Thanks for your help

Can you show a screenshot of the Active Connections as well as the firewall logs (Firewall → Common Tasks → View firewall alerts)?