# Secure ntp.conf against DDoS abuse

**URL:** <https://community.ntppool.org/t/secure-ntp-conf-against-ddos-abuse/179>\
**Category:** Server operators\
**Created:** [March 29, 2017, 6:51pm UTC](https://community.ntppool.org/t/secure-ntp-conf-against-ddos-abuse/179 "2017-03-29T18:51:45Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![iocc](https://avatars.discourse-cdn.com/v4/letter/i/ba9def/32.png) [@iocc](https://community.ntppool.org/u/iocc)\
**Post date:** [March 29, 2017, 6:51pm UTC](https://community.ntppool.org/t/secure-ntp-conf-against-ddos-abuse/179/1 "2017-03-29T18:51:45Z")

</div>

Is there anything missing in my ntp.conf so ntpd can be used to DDoS?  
Right now I got this:

restrict default kod nomodify notrap nopeer noquery  
disable monitor

Because just a few days ago I almost killed my co-lo’s router with a  
900 Mbit/s DDoS against some cn IPs. Example data from tcpdump that I got from  
co-lo:

10:45:42.150376 IP myip.123 \> 121.40.75.145.55699: NTPv2, Reserved, length 440  
10:45:42.100010 IP myip.123 \> 116.31.125.15.24292: NTPv2, Reserved, length 440

Right now ntp is blocked until I find the source of this problem.

---

<div class="post-metadata">

**Author:** ![avij](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/avij/32/197_2.png) [@avij](https://community.ntppool.org/u/avij)\
**Post date:** [March 30, 2017, 11:38am UTC](https://community.ntppool.org/t/secure-ntp-conf-against-ddos-abuse/179/2 "2017-03-30T11:38:01Z")

</div>

What I have here is:

restrict default limited nomodify notrap nopeer noquery  
restrict -6 default limited nomodify notrap nopeer noquery

You don’t seem to have “limited” in your configuration, which is the key. I also don’t bother sending KoD packets (the kod keyword) at all.

I also have “discard average 5 minimum 1” in my own config. Quoting:

[quote]average — specifies the minimum average packet spacing to be permitted, it accepts an argument in log2 seconds. The default value is 3 (2^3 equates to 8 seconds).

minimum — specifies the minimum packet spacing to be permitted, it accepts an argument in log2 seconds. The default value is 1 (2^1 equates to 2 seconds).  
[/quote]  
2^5 is 32.

I also drop all UDP traffic that originates from some IP’s port 53 (DNS) to my server’s port 123 (NTP). I find it unlikely that any such traffic would be legit. I do this with ip(6)tables.

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/mnordhoff/32/1470_2.png) [@mnordhoff](https://community.ntppool.org/u/mnordhoff)\
**Post date:** [March 30, 2017, 3:06pm UTC](https://community.ntppool.org/t/secure-ntp-conf-against-ddos-abuse/179/3 "2017-03-30T15:06:22Z")

</div>

Did you also have 900 Mbps _inbound_ traffic? Nothing especially bad should happen with that `restrict` rule.

> [@avij](#):
>
> I also drop all UDP traffic that originates from some IP’s port 53 (DNS) to my server’s port 123 (NTP). I find it unlikely that any such traffic would be legit. I do this with ip(6)tables.

Some such traffic will be legitimate. Some NAT gateways use _any_ port at random, including double-digit ones.

---

<div class="post-metadata">

**Author:** ![avij](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/avij/32/197_2.png) [@avij](https://community.ntppool.org/u/avij)\
**Post date:** [March 30, 2017, 6:59pm UTC](https://community.ntppool.org/t/secure-ntp-conf-against-ddos-abuse/179/4 "2017-03-30T18:59:05Z")

</div>

> [@mnordhoff](#):
>
> Some such traffic will be legitimate. Some NAT gateways use _any_ port at random, including double-digit ones.

No doubt, but this is about probabilities. When you drop or limit any kind of NTP traffic, it is always possible that someone’s legit traffic will also get dropped. If you want to be 100% certain that all legit requests get answered, don’t limit any traffic. However, that may also lead to your NTP server being used in a DDoS. So it’s a compromise.

By your logic (port chosen randomly), packets from source ports 53 and 54 (which is apparently “xns-ch, XNS Clearinghouse”) should occur approximately as often, right? On one of my servers, I received 402 packets from port 53 and 14 packets from port 54 in an hour. This gives me the impression that for many (but not all) of those packets originating from port 53, the port wasn’t chosen randomly.

Edit: For full disclosure, the server received around 500k requests during that hour, so around 0.1% of requests got dropped due to that rule. I can live with this.

---

<div class="post-metadata">

**Author:** ![paulgear](https://avatars.discourse-cdn.com/v4/letter/p/ad7895/32.png) [@paulgear](https://community.ntppool.org/u/paulgear)\
**Post date:** [March 31, 2017, 4:26am UTC](https://community.ntppool.org/t/secure-ntp-conf-against-ddos-abuse/179/5 "2017-03-31T04:26:36Z")

</div>

> [@avij](#):
>
> What I have here is:
> 
> restrict default limited nomodify notrap nopeer noquery  
> restrict -6 default limited nomodify notrap nopeer noquery
> 
> You don’t seem to have “limited” in your configuration, which is the key. I also don’t bother sending KoD packets (the kod keyword) at all.  
> …

At least on the versions of ntp I use, you must specify “kod” in order to use “limited”.

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/mnordhoff/32/1470_2.png) [@mnordhoff](https://community.ntppool.org/u/mnordhoff)\
**Post date:** [March 31, 2017, 5:40am UTC](https://community.ntppool.org/t/secure-ntp-conf-against-ddos-abuse/179/6 "2017-03-31T05:40:47Z")

</div>

> [@paulgear](#):
>
> At least on the versions of ntp I use, you must specify “kod” in order to use “limited”.

It should be the other way around.

- If you only set `kod`: Nothing happens. It’s ignored. There is no rate limiting.
- If you only set `limited`: Rate limiting is enabled. Excessive queries will be dropped, but KoD replies will not be sent.
- If you set both `kod` and `limited`: KoD and rate limiting are enabled. Sometimes excessive queries will be silently dropped, sometimes KoD replies will be sent.

---

<div class="post-metadata">

**Author:** ![iocc](https://avatars.discourse-cdn.com/v4/letter/i/ba9def/32.png) [@iocc](https://community.ntppool.org/u/iocc)\
**Post date:** [April 3, 2017, 8:14pm UTC](https://community.ntppool.org/t/secure-ntp-conf-against-ddos-abuse/179/7 "2017-04-03T20:14:58Z")

</div>

> [@avij](#):
>
> What I have here is:
> 
> restrict default limited nomodify notrap nopeer noquery  
> restrict -6 default limited nomodify notrap nopeer noquery
> 
> You don’t seem to have “limited” in your configuration, which is the key. I also don’t bother sending KoD packets (the kod keyword) at all.

Thanks, I have added “limited” now. I also choose to not send KoD and removed “kod”.

---

<div class="post-metadata">

**Author:** ![iocc](https://avatars.discourse-cdn.com/v4/letter/i/ba9def/32.png) [@iocc](https://community.ntppool.org/u/iocc)\
**Post date:** [April 3, 2017, 8:18pm UTC](https://community.ntppool.org/t/secure-ntp-conf-against-ddos-abuse/179/8 "2017-04-03T20:18:16Z")

</div>

> [@mnordhoff](#):
>
> Did you also have 900 Mbps inbound traffic? Nothing especially bad should happen with that restrict rule.

I dont know but I find it unlikely. Well, something bad did happend anyway.

---

<div class="post-metadata">

**Author:** ![iocc](https://avatars.discourse-cdn.com/v4/letter/i/ba9def/32.png) [@iocc](https://community.ntppool.org/u/iocc)\
**Post date:** [April 4, 2017, 2:34pm UTC](https://community.ntppool.org/t/secure-ntp-conf-against-ddos-abuse/179/9 "2017-04-04T14:34:52Z")

</div>

> [@avij](#):
>
> What I have here is:
> 
> restrict default limited nomodify notrap nopeer noquery  
> restrict -6 default limited nomodify notrap nopeer noquery
> 
> You don’t seem to have “limited” in your configuration, which is the key. I also don’t bother sending KoD packets (the kod keyword) at all.

A new problem appeared, monitor cant be disabled when I use limited.  
ntpd says: “monitor cannot be disabled with limited restrict”

Does that mean its vuln to monlist DDoS or will limited take care of  
that problem?

Right now I got this cfg:

restrict default limited nomodify notrap nopeer noquery  
restrict -6 default limited nomodify notrap nopeer noquery  
disable monitor

restrict 127.0.0.1  
restrict -6 ::1

---

<div class="post-metadata">

**Author:** ![avij](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/avij/32/197_2.png) [@avij](https://community.ntppool.org/u/avij)\
**Post date:** [April 5, 2017, 2:54pm UTC](https://community.ntppool.org/t/secure-ntp-conf-against-ddos-abuse/179/10 "2017-04-05T14:54:20Z")

</div>

> [@iocc](#):
>
> Does that mean its vuln to monlist DDoS or will limited take care of  
> that problem?

You’re safe. noquery in the restrict options means your server won’t answer to such queries.

---

<div class="post-metadata">

**Author:** ![paulgear](https://avatars.discourse-cdn.com/v4/letter/p/ad7895/32.png) [@paulgear](https://community.ntppool.org/u/paulgear)\
**Post date:** [September 13, 2017, 11:13am UTC](https://community.ntppool.org/t/secure-ntp-conf-against-ddos-abuse/179/11 "2017-09-13T11:13:58Z")

</div>

Ah yes - I had them the wrong way around.
