Re: [chrony-users] NTS dropped packets

[ Thread Index | Date Index | More chrony.tuxfamily.org/chrony-users Archives ]


On Mon, Nov 30, 2020 at 07:22:47PM +0100, Kurt Roeckx wrote:
> Hi,
> 
> I'm seeing dropped packets when talking to an NTS enabled server.
> But I'm only seeing it on my home network, not on my server in the
> datacenter. I currently see this using ptbnts1.ptb.de. I think I
> had the same problem with nts.ntp.se, but it seems I changed from
> an IPv4 address to an IPv6 address there and don't see the issue
> since.

Some major network operators are blocking or rate limiting NTP packets
as a mitigation against the ntpd mode-6 amplification attacks. In some
networks it specifically applies to longer NTP packets. There is not
much we can do except move to a different port, as proposed in the
alternative-port draft.

-- 
Miroslav Lichvar


-- 
To unsubscribe email chrony-users-request@xxxxxxxxxxxxxxxxxxxx 
with "unsubscribe" in the subject.
For help email chrony-users-request@xxxxxxxxxxxxxxxxxxxx 
with "help" in the subject.
Trouble?  Email listmaster@xxxxxxxxxxxxxxxxxxxx.


Mail converted by MHonArc 2.6.19+ http://listengine.tuxfamily.org/