Am Samstag, den 04.04.2009, 22:47 +0200 schrieb Martin Schröder: > > I've seen huge spikes from Turkey before on our previous server, but > that one had a smaller uplink and no provider checking for abuse. :-) > > Is this plausible?
There are peaks also on my server (ntp.dianacht.de) and and in every peak there is an above average rate of turkish clients: http://www.dianacht.de/ntp/country.php Most of them are from "Turk Telekom" and most of them are clients who appear just once a day in the logs. I tried to analyse this traffic about one year ago, but I didn't find a solution (http://schnipsel.dianacht.de/2008/04/19/tuerkische-peaks / sorry, in german). Since that time the peaks seem to get more flat, but they are still there. Perhaps the best way to solve the problem is to exclude udp-packets with source port 123 from the list of "scans"... Max _______________________________________________ timekeepers mailing list [email protected] https://fortytwo.ch/mailman/cgi-bin/listinfo/timekeepers
