# Spikes in traffic the past couple days?

**URL:** <https://community.ntppool.org/t/spikes-in-traffic-the-past-couple-days/908>\
**Category:** Server operators\
**Created:** [September 24, 2018, 2:40pm UTC](https://community.ntppool.org/t/spikes-in-traffic-the-past-couple-days/908 "2018-09-24T14:40:59Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![littlejason99](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/littlejason99/32/242_2.png) [@littlejason99](https://community.ntppool.org/u/littlejason99)\
**Post date:** [September 24, 2018, 2:40pm UTC](https://community.ntppool.org/t/spikes-in-traffic-the-past-couple-days/908/1 "2018-09-24T14:40:59Z")

</div>

My server usually has about 200 packets/sec traffic (50Mb/US setting), and I see the occasional spike to around 400-500 which is no big deal. However, day before yesterday there was a pretty significant, but short, jump to 1.4k/ps, and last night a spike to over 1k/ps that lasted about 20min+…

![graph_image](https://us1.discourse-cdn.com/flex016/uploads/ntppool/original/1X/591d5b5f12702fb64d579d785c17128c823f7497.png)

Times in the graph are US/CDT.

Those spikes will fill up my conntrack table and the server will start dropping packets…

My 2nd pool server I don’t have graphs like this, but did notice a huge drop in its score around the same time so that is a distinct possibility it was hit too.

Anyone else with pool servers seen these lately?

---

<div class="post-metadata">

**Author:** ![avij](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/avij/32/197_2.png) [@avij](https://community.ntppool.org/u/avij)\
**Post date:** [September 24, 2018, 4:17pm UTC](https://community.ntppool.org/t/spikes-in-traffic-the-past-couple-days/908/2 "2018-09-24T16:17:56Z")

</div>

Regarding conntrack table – I would highly recommend NOT doing connection tracking for NTP traffic. I have this in my custom firewall script:

```
/sbin/iptables -t raw -A PREROUTING -p udp --dport 123 -j CT --notrack
/sbin/ip6tables -t raw -A PREROUTING -p udp --dport 123 -j CT --notrack
/sbin/iptables -t raw -A OUTPUT -p udp --sport 123 -j CT --notrack
/sbin/ip6tables -t raw -A OUTPUT -p udp --sport 123 -j CT --notrack

```

Not doing connection tracking does not prevent you from filtering the NTP traffic in some other way, if you prefer.

---

<div class="post-metadata">

**Author:** ![littlejason99](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/littlejason99/32/242_2.png) [@littlejason99](https://community.ntppool.org/u/littlejason99)\
**Post date:** [September 24, 2018, 4:50pm UTC](https://community.ntppool.org/t/spikes-in-traffic-the-past-couple-days/908/3 "2018-09-24T16:50:28Z")

</div>

Thanks for the tip! I’ll see if I can’t get that worked into my firewall today.

---

<div class="post-metadata">

**Author:** ![littlejason99](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/littlejason99/32/242_2.png) [@littlejason99](https://community.ntppool.org/u/littlejason99)\
**Post date:** [September 26, 2018, 2:27pm UTC](https://community.ntppool.org/t/spikes-in-traffic-the-past-couple-days/908/4 "2018-09-26T14:27:05Z")

</div>

Another odd spike went up to 650/ps at about 1:10am central. No messages about dropped packets so I think that fixed it! Thanks again.
