On Wed, 3 Oct 2007, Nelson Minar wrote:

>
> I was surprised by this behaviour; I'd assumed the abusive clients were
> so insane they wouldn't even notice if the server was up. I have full
> packet captures for this whole period; would it be useful to try to
> figure out precisely which clients left me? I guess it's mostly foolish
> to try to figure out what's going on with anonymous Internet clients,
> but I'm curious.
>
> (Speaking of curious, I've now rigged my NTP server to record a
> timestamp and source address for every single request, as well as full
> pcap captures for 1/100th of my requests. I intend to log this for
> months in the hopes it will later be useful for someone researching pool
> usage. It's about 7 megabytes / day of disk space.)
>

Is your traffic going through a stateful firewall before getting to your 
ntpd or is your ntpd server running with its own public IP   ?


Louis
http://blogtech.oc9.com
_______________________________________________
timekeepers mailing list
[email protected]
https://fortytwo.ch/mailman/cgi-bin/listinfo/timekeepers

Reply via email to