[193041] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Recent NTP pool traffic increase

daemon@ATHENA.MIT.EDU (Blake Hudson)
Thu Dec 15 21:06:23 2016

X-Original-To: nanog@nanog.org
To: nanog@nanog.org
From: Blake Hudson <blake@ispn.net>
Date: Thu, 15 Dec 2016 17:00:27 -0600
In-Reply-To: <BL2PR05MB23064A7EFF95B991FFDD4AD2D09D0@BL2PR05MB2306.namprd05.prod.outlook.com>
Errors-To: nanog-bounces@nanog.org

I would think if a service provider failed, the stats would bear that 
out. For example, if one of the top ISPs in the world was forwarding 
requests, then you would likely see an increase in the number of queries 
generated from IP addresses registered to that organization. A similar 
effect could occur if a large ISP recently started distributing NTP 
servers as part of their DHCP options when they had not previously. If 
historical query data is not available, the current data could be used 
to make an educated guess and follow up on the likely data trails as 
currently visible.

I would also not rule out the possibility that a Netgear, DLink, 
T-mobile or some other vendor or distributor of access gear pushed out a 
firmware update which enabled NTP when it previously was disabled or 
otherwise changed a device's NTP settings or behavior.

--Blake

Jose Gerardo Perales Soto wrote on 12/15/2016 4:45 PM:
> Hi,
>
> We've recently experienced a traffic increase on the NTP queries to NTP pool project (pool.ntp.org) servers. One theory is that some service provider NTP infraestructure failed approximately 2 days ago and traffic is now being redirected to servers belonging to the NTP pool project.
>
> Does anyone from the service provider community have any comments?
>
> Gerardo Perales


home help back first fref pref prev next nref lref last post