# Ip monitor list

**URL:** <https://community.ntppool.org/t/ip-monitor-list/2818>\
**Category:** Server operators\
**Tags:** monitoring\
**Created:** [March 30, 2023, 8:25am UTC](https://community.ntppool.org/t/ip-monitor-list/2818 "2023-03-30T08:25:48Z")\
**Posts on this page:** 1\
**Showing post:** 11

<div class="post-metadata">

**Author:** ![erayd](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/erayd/32/85_2.png) [@erayd](https://community.ntppool.org/u/erayd)\
**Post date:** [April 3, 2023, 10:47pm UTC](https://community.ntppool.org/t/ip-monitor-list/2818/11 "2023-04-03T22:47:26Z")

</div>

In my opinion it’s worthwhile having some sort of automated throttling of clients, even if just as a defense against bugs. As an example, 20,000 packets / sec for each problematic client is not insignificant - see the Fortigate bug below. Rules that chop the peaks off that kind of load can be quite helpful.

> [@NTP bursts from FortiGate firewalls](https://community.ntppool.org/t/ntp-bursts-from-fortigate-firewalls/1661):
>
> (This summarizes a problem mentioned in other discussions.) A recent enhancement to FortiOS, used in the FortiGate firewall, did not handle NTP DNS changes correctly. When DNS mapping changed FortiGate firewalls sent 10 second duration NTP bursts at rates that could exceed 20,000 requests/second. NTP Pool servers were impacted due to the use of DNS load balancing. Our team monitored three NTP pool servers and detected over 150 FortiGate devices sending NTP bursts. FortiGate support identified…

---

_[View the full topic](https://community.ntppool.org/t/ip-monitor-list/2818)._
