Bas and I each have a client in the BE zone (actually BE+Europe+Global). Both provide good time accuracy & have scores of 20. Both have netspeed of 3Gbps. I’d like to verify that our clients get similar traffic. Bas suggested using this forum for the discussion, as others may be interested.
This discussion concerns the incoming traffic only. There are ongoing discussions concerning routers, IP tables, firewalls, etc. I’m reading those threads, but I have little to contribute.
I’ll start with my server:
The average request rate is 1000-1500 /second, though there are significant outliers. Other averaging intervals (e.g., one second) look noisy. I expect to see a diurnal variation emerge as the tests continue.
I’d like to discuss abusive clients. One client, 194.78.232.126, sent 110+ requests/second for over a week. Some other clients send around 10 requests/second
Some people may remember my complaints about abusive Fortigate traffic This was due to an acknowledged bug. The vendor discussed the problem with me and the problem was fixed in an update. I started noticing similar NTP bursts coming from clients in Lithuania, some of which identify themselves as using Fortinet software. The vendors no longer answers my emails. How does this impact Belgium? One issue is that these other clients may burst simultaneously. E.g., here are 4 clients hitting my server at the same time.
2026-01-13 22:30:14 46.36.89.196 1145 FORT These clients are located in Lithuania
2026-01-13 22:30:14 46.36.90.231 1536 FORT
2026-01-13 22:30:14 46.36.90.211 1863 FORT
2026-01-13 22:30:14 46.36.90.216 3078 FORT
About 0.8% of my server’s traffic comes these Lithuanian bursters.
I’ve seen up to 15 abusive clients bursting simultaneously. I suspect other zones in Europe are seeing similar traffic.



