Howto deal with bad NTP-Client / Attacker?

How long does it do that for?

If it’s brief, I wouldn’t worry about it.

I have an automated ruleset on my edge firewall that deals with the larger offenders:

1 Like