Sometimes I get huge burst of NTP packets from certain servers.
Here is part of the packet trace:
11:27:28.156386 IP 212.147.28.70.123 > 156.106.214.52.123: NTPv4, Client, length 48
11:27:28.156460 IP 156.106.214.52.123 > 212.147.28.70.123: NTPv4, Server, length 48
11:28:59.184211 IP 212.147.28.70.123 > 156.106.214.52.123: NTPv4, Client, length 48
11:28:59.184267 IP 156.106.214.52.123 > 212.147.28.70.123: NTPv4, Server, length 48
11:29:01.193556 IP 212.147.28.70.123 > 156.106.214.52.123: NTPv4, Client, length 48
11:29:01.193663 IP 156.106.214.52.123 > 212.147.28.70.123: NTPv4, Server, length 48
11:29:03.206575 IP 212.147.28.70.123 > 156.106.214.52.123: NTPv4, Client, length 48
11:29:03.206650 IP 156.106.214.52.123 > 212.147.28.70.123: NTPv4, Server, length 48
11:29:05.229603 IP 212.147.28.70.123 > 156.106.214.52.123: NTPv4, Client, length 48
11:29:05.229661 IP 156.106.214.52.123 > 212.147.28.70.123: NTPv4, Server, length 48
11:29:07.244921 IP 212.147.28.70.123 > 156.106.214.52.123: NTPv4, Client, length 48
11:29:07.245097 IP 156.106.214.52.123 > 212.147.28.70.123: NTPv4, Server, length 48
11:29:57.198813 IP 212.147.28.70.123 > 156.106.214.52.123: NTPv4, Client, length 48
11:29:57.198828 IP 212.147.28.70.123 > 156.106.214.52.123: NTPv4, Client, length 48
11:29:57.198869 IP 156.106.214.52.123 > 212.147.28.70.123: NTPv4, Server, length 48
11:29:57.198888 IP 156.106.214.52.123 > 212.147.28.70.123: NTPv4, Server, length 48
11:29:57.199473 IP 212.147.28.70.123 > 156.106.214.52.123: NTPv4, Client, length 48
11:29:57.199553 IP 156.106.214.52.123 > 212.147.28.70.123: NTPv4, Server, length 48
11:29:57.199748 IP 212.147.28.70.123 > 156.106.214.52.123: NTPv4, Client, length 48
11:29:57.199819 IP 156.106.214.52.123 > 212.147.28.70.123: NTPv4, Server, length 48
11:29:57.200372 IP 212.147.28.70.123 > 156.106.214.52.123: NTPv4, Client, length 48
11:29:57.200434 IP 156.106.214.52.123 > 212.147.28.70.123: NTPv4, Server, length 48
11:29:57.200839 IP 212.147.28.70.123 > 156.106.214.52.123: NTPv4, Client, length 48
11:29:57.200935 IP 156.106.214.52.123 > 212.147.28.70.123: NTPv4, Server, length 48
11:29:57.201280 IP 212.147.28.70.123 > 156.106.214.52.123: NTPv4, Client, length 48
11:29:57.201349 IP 156.106.214.52.123 > 212.147.28.70.123: NTPv4, Server, length 48
11:29:57.201985 IP 212.147.28.70.123 > 156.106.214.52.123: NTPv4, Client, length 48
11:29:57.202073 IP 156.106.214.52.123 > 212.147.28.70.123: NTPv4, Server, length 48
11:29:57.203261 IP 212.147.28.70.123 > 156.106.214.52.123: NTPv4, Client, length 48
11:29:57.203276 IP 212.147.28.70.123 > 156.106.214.52.123: NTPv4, Client, length 48
11:29:57.203333 IP 156.106.214.52.123 > 212.147.28.70.123: NTPv4, Server, length 48
11:29:57.203352 IP 156.106.214.52.123 > 212.147.28.70.123: NTPv4, Server, length 48
11:29:57.203897 IP 212.147.28.70.123 > 156.106.214.52.123: NTPv4, Client, length 48
11:29:57.203982 IP 156.106.214.52.123 > 212.147.28.70.123: NTPv4, Server, length 48
11:29:57.204062 IP 212.147.28.70.123 > 156.106.214.52.123: NTPv4, Client, length 48
11:29:57.204176 IP 156.106.214.52.123 > 212.147.28.70.123: NTPv4, Server, length 48
11:29:57.204707 IP 212.147.28.70.123 > 156.106.214.52.123: NTPv4, Client, length 48
11:29:57.204781 IP 156.106.214.52.123 > 212.147.28.70.123: NTPv4, Server, length 48
11:29:57.205086 IP 212.147.28.70.123 > 156.106.214.52.123: NTPv4, Client, length 48
11:29:57.205158 IP 156.106.214.52.123 > 212.147.28.70.123: NTPv4, Server, length 48
11:29:57.205875 IP 212.147.28.70.123 > 156.106.214.52.123: NTPv4, Client, length 48
11:29:57.205943 IP 156.106.214.52.123 > 212.147.28.70.123: NTPv4, Server, length 48
The per second statistics for the client 212.147.28.70 (first column is the number of packets in both directions):
2 11:27:28
2 11:28:59
2 11:29:01
2 11:29:03
2 11:29:05
2 11:29:07
3580 11:29:57
6267 11:29:58
6274 11:29:59
6271 11:30:00
6266 11:30:01
6252 11:30:02
6245 11:30:03
6270 11:30:04
6269 11:30:05
6306 11:30:06
1222 11:30:07
My ntp.conf has: restrict default nomodify notrap nopeer noquery
Do you know by chance is there any broken NTP server implementation in use on the Internet with similar behavior?