# What is a reasonable limit?

**URL:** <https://community.ntppool.org/t/what-is-a-reasonable-limit/2460>\
**Category:** Uncategorized\
**Created:** [June 20, 2022, 4:22pm UTC](https://community.ntppool.org/t/what-is-a-reasonable-limit/2460 "2022-06-20T16:22:51Z")\
**Posts on this page:** 1\
**Showing post:** 11

<div class="post-metadata">

**Author:** ![erayd](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/erayd/32/85_2.png) [@erayd](https://community.ntppool.org/u/erayd)\
**Post date:** [June 22, 2022, 6:39am UTC](https://community.ntppool.org/t/what-is-a-reasonable-limit/2460/11 "2022-06-22T06:39:54Z")

</div>

I personally add anything that hits me with more than 1000 reqs/sec to a 24hr blocklist at my network edge (prevents things like the fortinet bursters sending problematic levels of traffic as far as my server, although I do still save the blocked requests for later analysis). They get a 3000 request burst before the policy is applied. Anything slower than that, I don’t worry about.

If reflection abuse becomes a significant problem, then I will revise that limit downwards.

My main rationale behind allowing that much traffic is to address the scenario where e.g. a few thousand shitty IoT clients try to synchronise from behind NAT all at the same time, or if there are few buggy devices that try to sync time in a fast loop. I doubt it happens often, but I’d still like to have my server available to service those requests, and to service the requests of other devices sharing a public IP with something buggy.

---

_[View the full topic](https://community.ntppool.org/t/what-is-a-reasonable-limit/2460)._
