On Wed, 3 Oct 2007, Nelson Minar wrote: > > I was surprised by this behaviour; I'd assumed the abusive clients were > so insane they wouldn't even notice if the server was up. I have full > packet captures for this whole period; would it be useful to try to > figure out precisely which clients left me? I guess it's mostly foolish > to try to figure out what's going on with anonymous Internet clients, > but I'm curious. > > (Speaking of curious, I've now rigged my NTP server to record a > timestamp and source address for every single request, as well as full > pcap captures for 1/100th of my requests. I intend to log this for > months in the hopes it will later be useful for someone researching pool > usage. It's about 7 megabytes / day of disk space.) >
Is your traffic going through a stateful firewall before getting to your ntpd or is your ntpd server running with its own public IP ? Louis http://blogtech.oc9.com _______________________________________________ timekeepers mailing list [email protected] https://fortytwo.ch/mailman/cgi-bin/listinfo/timekeepers
