I have an IPv4 NTP server running in the pool for several months now, and it has been quite a problem for me that it seems there are large amount of clients which run some sort of synchronization script on a fixed absolute time and interval (every 15 minutes, specifically 0, 15, 30, 45 minute of each hour), which causes load spikes to the server and also triggers cloud provider’s DDoS protection to kick in (see below).
The servers are running in CN zone, and I’m just curious about how other people deal with this kind of clients and is this specific for CN zone or global.
EDIT 1: These spikes would have been higher without ISP’s DDoS services. I have recorded >200Mbps (200kpps) traffic on DDoS dashboard when the bandwidth is configured to 1.5Mbps on management portal.

