Am Samstag, den 04.04.2009, 22:47 +0200 schrieb Martin Schröder:

> 
> I've seen huge spikes from Turkey before on our previous server, but
> that one had a smaller uplink and no provider checking for abuse. :-)
> 
> Is this plausible?

There are peaks also on my server (ntp.dianacht.de) and and in every
peak there is an above average rate of turkish clients:
http://www.dianacht.de/ntp/country.php

Most of them are from "Turk Telekom" and most of them are clients who
appear just once a day in the logs. I tried to analyse this traffic
about one year ago, but I didn't find a solution
(http://schnipsel.dianacht.de/2008/04/19/tuerkische-peaks / sorry, in
german). Since that time the peaks seem to get more flat, but they are
still there.

Perhaps the best way to solve the problem is to exclude udp-packets with
source port 123 from the list of "scans"...


Max




_______________________________________________
timekeepers mailing list
[email protected]
https://fortytwo.ch/mailman/cgi-bin/listinfo/timekeepers

Reply via email to