# Realistic max packets/sec per source IP?

**URL:** <https://community.ntppool.org/t/realistic-max-packets-sec-per-source-ip/1648>\
**Category:** Server operators\
**Created:** [April 26, 2020, 2:04am UTC](https://community.ntppool.org/t/realistic-max-packets-sec-per-source-ip/1648 "2020-04-26T02:04:57Z")\
**Posts on this page:** 2\
**Page:** 2

<div class="post-metadata">

**Author:** ![elljay](https://avatars.discourse-cdn.com/v4/letter/e/5fc32e/32.png) [@elljay](https://community.ntppool.org/u/elljay)\
**Post date:** [May 10, 2020, 8:21am UTC](https://community.ntppool.org/t/realistic-max-packets-sec-per-source-ip/1648/22 "2020-05-10T08:21:37Z")

</div>

Good news about the firewall software update.

I went for a “quick and dirty” couple of lines in iptables. Similar rule for IPv6. The IPv4 rules gets a surprisingly high number of hits!

-A INPUT -p udp --destination-port 123 -d -m hashlimit --hashlimit-name ipv4-ntp-limit --hashlimit-above 3/s --hashlimit-burst 10 --hashlimit-mode srcip -j LOG --log-prefix "IPv4 NTP RL(3/s): "  
-A INPUT -p udp --destination-port 123 -d -m hashlimit --hashlimit-name ipv4-ntp-limit --hashlimit-above 3/s --hashlimit-burst 10 --hashlimit-mode srcip -j DROP

---

<div class="post-metadata">

**Author:** ![NTPman](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/ntpman/32/450_2.png) [@NTPman](https://community.ntppool.org/u/NTPman)\
**Post date:** [May 25, 2020, 6:49pm UTC](https://community.ntppool.org/t/realistic-max-packets-sec-per-source-ip/1648/23 "2020-05-25T18:49:35Z")

</div>

My NTP reply packet rate limit is now 0 pckt/sec. Based on the syslog output of [https://github.com/bruncsak/ntpflood-report](https://github.com/bruncsak/ntpflood-report) a simple script puts into the iptables the DROP rule. It blocks only about 160 IP addresses.

[Previous page](https://community.ntppool.org/t/realistic-max-packets-sec-per-source-ip/1648.md?page=1)
