# Usual traffic intensity

**URL:** <https://community.ntppool.org/t/usual-traffic-intensity/2504>\
**Category:** Uncategorized\
**Created:** [August 2, 2022, 12:57pm UTC](https://community.ntppool.org/t/usual-traffic-intensity/2504 "2022-08-02T12:57:39Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![roman](https://avatars.discourse-cdn.com/v4/letter/r/ed8c4c/32.png) [@roman](https://community.ntppool.org/u/roman)\
**Post date:** [August 2, 2022, 12:57pm UTC](https://community.ntppool.org/t/usual-traffic-intensity/2504/1 "2022-08-02T12:57:39Z")

</div>

Hello,  
maybe a silly question:  
is it normal NTP traffic like this?  
About 2 GB daily?  
It is too much for me.

 ![traffic](https://us1.discourse-cdn.com/flex016/uploads/ntppool/original/1X/0668bd702058e8ed27fb5a8eeb9e2b895c4663c8.png)

---

<div class="post-metadata">

**Author:** ![alica](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/alica/32/337_2.png) [@alica](https://community.ntppool.org/u/alica)\
**Post date:** [August 2, 2022, 1:30pm UTC](https://community.ntppool.org/t/usual-traffic-intensity/2504/2 "2022-08-02T13:30:49Z")

</div>

It depends on your zone config and announced netspeed setting. If your server located in a zone with low server:client ratio then your throughput will be high.  
 ![Screenshot 2022-08-02 211818](https://us1.discourse-cdn.com/flex016/uploads/ntppool/original/1X/2149dc563386a6e2d07d12b2e01ff8b7985c801e.png)  
Above image states the daily average of 4048 outgoing NTP packets per second. If every packet is 100 bytes then the whole daily throughput will be:

```auto
100(byte)*4048(packets per second)*86400(second)=34974720000(byte)=32.57274(GB)

```

If the figure looks horrible to you, feel free to lower your netspeed setting.

---

<div class="post-metadata">

**Author:** ![HAHAHAHA](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/hahahaha/32/2475_2.png) [@HAHAHAHA](https://community.ntppool.org/u/HAHAHAHA)\
**Post date:** [August 2, 2022, 2:50pm UTC](https://community.ntppool.org/t/usual-traffic-intensity/2504/3 "2022-08-02T14:50:22Z")

</div>

The “normal” for me during peak hour on a weekday (Asia, at night) : \>100K requests / second.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/ntppool/original/1X/f3aec48a6f11e6fad1c388de0e453a0ed9712f64.png)

---

<div class="post-metadata">

**Author:** ![apuls](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/apuls/32/1467_2.png) [@apuls](https://community.ntppool.org/u/apuls)\
**Post date:** [August 2, 2022, 3:27pm UTC](https://community.ntppool.org/t/usual-traffic-intensity/2504/4 "2022-08-02T15:27:50Z")

</div>

Hi roman,

as the other already saied - yes and it depends on the zone.  
What’s your current “speed” setting of your server (ntppool management interface) ? If you set the speed below 1MBit or 768kbit (didn’t remeber it right now) your server will be removed from the global pool.  
I would suggest put it to the lowest speed as possible and wait some time. ex: if it’s ok after a week set it to the next higher speed level and wait again.

---

<div class="post-metadata">

**Author:** ![henri.martin](https://avatars.discourse-cdn.com/v4/letter/h/e36b37/32.png) [@henri.martin](https://community.ntppool.org/u/henri.martin)\
**Post date:** [August 5, 2022, 5:22am UTC](https://community.ntppool.org/t/usual-traffic-intensity/2504/5 "2022-08-05T05:22:24Z")

</div>

We have 2 Stratum 1 : The average incoming packets/sec is between 8000 (8k) and 16000 (16k) but with some peaks around 200k/sec.  
Without any optional extensions the incoming and outgoing packets are 76 octets in length. =\> Minimum of 52 GB/ day for 8k/sec.(peak = 1.3 TB/day)  
This is not a problem for the ntp server … but can become a problem for the firewall or some limited networks.

---

<div class="post-metadata">

**Author:** ![roman](https://avatars.discourse-cdn.com/v4/letter/r/ed8c4c/32.png) [@roman](https://community.ntppool.org/u/roman)\
**Post date:** [August 6, 2022, 9:26am UTC](https://community.ntppool.org/t/usual-traffic-intensity/2504/6 "2022-08-06T09:26:08Z")

</div>

Well, ok  
I have set connection speed to 10 Mbit and traffic looks like that:

 ![traffic](https://us1.discourse-cdn.com/flex016/uploads/ntppool/original/1X/a90607898598a26f083efdee57db88402eec528e.png)

Surprisingly uneven.

---

<div class="post-metadata">

**Author:** ![roman](https://avatars.discourse-cdn.com/v4/letter/r/ed8c4c/32.png) [@roman](https://community.ntppool.org/u/roman)\
**Post date:** [August 6, 2022, 9:32am UTC](https://community.ntppool.org/t/usual-traffic-intensity/2504/7 "2022-08-06T09:32:23Z")

</div>

Hello,  
can I ask you what software you use for draw such a graph?  
Is there any commonly available software that monitors NTP server traffic and saves the data to a file?  
I wrote a program as a service (Centos Linux) that reads data from chronyc serverstats and creates a CSV file.  
But it would probably be better to use some standard software, but I don’t know of any.

---

<div class="post-metadata">

**Author:** ![alica](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/alica/32/337_2.png) [@alica](https://community.ntppool.org/u/alica)\
**Post date:** [August 6, 2022, 3:22pm UTC](https://community.ntppool.org/t/usual-traffic-intensity/2504/8 "2022-08-06T15:22:56Z")

</div>

> [@roman](#):
>
> Hello,  
> can I ask you what software you use for draw such a graph?

There was a script found from the old ntppool mail list. I modified it and cron every 5 minutes to create data usable for MRTG. (I am too lazy to learn new monitoring tools like RRDtool and Munin… People said there were NTP plugins available for them.) The original [lists.ntp.org](http://lists.ntp.org) site is now defunct so the original message from a backup site follows:  
[[Pool] Traffic graphs (was: Taking down my NTP server in Turkey)](https://www.mail-archive.com/pool@lists.ntp.org/msg00935.html)

---

<div class="post-metadata">

**Author:** ![apuls](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/apuls/32/1467_2.png) [@apuls](https://community.ntppool.org/u/apuls)\
**Post date:** [August 6, 2022, 6:56pm UTC](https://community.ntppool.org/t/usual-traffic-intensity/2504/9 "2022-08-06T18:56:29Z")

</div>

As alica already said there are “some” tools.  
Munin with plugins

- [ntp\_packets | Munin Plugin Gallery](https://gallery.munin-monitoring.org/plugins/munin-contrib/ntp_packets/)
- [chrony\_status | Munin Plugin Gallery](https://gallery.munin-monitoring.org/plugins/munin-contrib/chrony_status/)

MRTG

- [Using MRTG to monitor NTP](https://www.satsignal.eu/ntp/NTPandMRTG.html)

you can also user Prometheus, InfluxDB as Datastorage which are feeded by your own scripts (like ntp / chrony stats or iptables/nftables packet counter) and visualized with Grafana.

It depends on how nice your graphs should be 🙂 , how much work you will spend to set it up and you want to acquire the stats (just local or via remote push / pull)

---

<div class="post-metadata">

**Author:** ![roman](https://avatars.discourse-cdn.com/v4/letter/r/ed8c4c/32.png) [@roman](https://community.ntppool.org/u/roman)\
**Post date:** [August 8, 2022, 1:37pm UTC](https://community.ntppool.org/t/usual-traffic-intensity/2504/10 "2022-08-08T13:37:05Z")

</div>

Still strange …  
What do you think, is this a normal situation or an attempt at DoS?

 ![chrony](https://us1.discourse-cdn.com/flex016/uploads/ntppool/original/1X/4da9ee77b86118dcc677d8775d73452d7a09fb92.png)

---

<div class="post-metadata">

**Author:** ![stevesommars](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/stevesommars/32/2075_2.png) [@stevesommars](https://community.ntppool.org/u/stevesommars)\
**Post date:** [August 9, 2022, 2:31am UTC](https://community.ntppool.org/t/usual-traffic-intensity/2504/11 "2022-08-09T02:31:24Z")

</div>

There are several sources of NTP request bursts, including:

- Network loops (L2 or L3) at the client
- Bursts from faulty [FortiGate](https://weberblog.net/fortigate-bug-firewalls-sending-excessive-requests-to-the-ntp-pool/) machines.
- Bursts from [systemd-timesyncd](https://github.com/systemd/systemd/issues/17470)
- bursts from carrier grade NAT resets  
plus others.

Some of these can be distinguished if a packet capture is available.

---

<div class="post-metadata">

**Author:** ![roman](https://avatars.discourse-cdn.com/v4/letter/r/ed8c4c/32.png) [@roman](https://community.ntppool.org/u/roman)\
**Post date:** [August 9, 2022, 7:11am UTC](https://community.ntppool.org/t/usual-traffic-intensity/2504/12 "2022-08-09T07:11:33Z")

</div>

Thank you for comprehensive answer. 🙂
