So during the bad periods you're getting 32000 requests / minute? That's an insane amount of traffic; what the heck are they doing? Do a bunch of requests come from a single misconfigured IP? Or somehow do they have 500,000+ clients all hitting you at a reasonable once every 17 minutes?
For what it's worth, I don't see this pattern in my US based pool server. I guess they're hitting the European DNS name? Rob Oats wrote: > I am in a similar position. I have not taken a decision as yet but I am > getting close to deciding whether to leave the pool or not. This is what the > dump file looked like on Sunday (and 90% originates from Turk Telekom); > Date Time req/minute abusive dns > 07/22/07 08:45:03 540 6 0 > 07/22/07 08:50:03 1317 6 0 > 07/22/07 09:01:47 14985 8 0 > 07/22/07 09:06:49 25203 7 0 > 07/22/07 09:11:47 31902 8 0 > 07/22/07 09:16:49 35385 8 0 > 07/22/07 09:21:47 34971 9 0 > 07/22/07 09:26:49 33201 9 0 > 07/22/07 09:31:48 30325 11 0 > 07/22/07 09:33:01 27794 8 0 > 07/22/07 09:35:08 24603 8 0 > 07/22/07 09:40:03 17214 8 0 > 07/22/07 09:45:07 10064 11 0 > 07/22/07 09:50:03 4816 12 0 > 07/22/07 09:55:02 3070 14 0 > 07/22/07 10:00:02 1840 15 0 > 07/22/07 10:05:02 1178 7 0 > 07/22/07 10:10:04 1014 10 0 > 07/22/07 10:22:23 16448 9 0 > 07/22/07 10:27:23 26199 8 0 > 07/22/07 10:33:16 32261 7 0 > 07/22/07 10:39:11 31962 9 1 d.ntpns.org > 07/22/07 10:44:11 30682 8 1 d.ntpns.org > 07/22/07 10:49:11 29766 13 1 d.ntpns.org > 07/22/07 10:54:16 30545 23 1 d.ntpns.org > 07/22/07 10:59:10 31824 36 1 d.ntpns.org > 07/22/07 11:04:11 34559 38 1 d.ntpns.org > 07/22/07 11:09:08 32583 2 1 d.ntpns.org > 07/22/07 11:14:08 32583 2 1 d.ntpns.org > 07/22/07 11:19:07 32583 2 1 d.ntpns.org > 07/22/07 11:24:07 32583 2 1 d.ntpns.org > 07/22/07 11:29:07 32583 2 1 d.ntpns.org > 07/22/07 11:34:07 32583 2 1 d.ntpns.org > 07/22/07 11:39:07 32583 2 1 d.ntpns.org > 07/22/07 11:44:07 32583 2 1 d.ntpns.org > 07/22/07 11:49:08 32583 2 1 d.ntpns.org > 07/22/07 11:54:08 32583 2 1 d.ntpns.org > 07/22/07 11:59:07 32583 2 1 d.ntpns.org > 07/22/07 12:04:07 32583 2 1 d.ntpns.org > 07/22/07 12:09:07 32583 2 1 d.ntpns.org > 07/22/07 12:14:08 32583 2 1 d.ntpns.org > 07/22/07 12:19:07 32583 2 1 d.ntpns.org > 07/22/07 12:24:07 32583 2 1 d.ntpns.org > 07/22/07 12:29:07 32583 2 1 d.ntpns.org > 07/22/07 12:34:08 32583 2 1 d.ntpns.org > 07/22/07 12:39:07 32583 2 1 d.ntpns.org > 07/22/07 12:44:08 32583 2 1 d.ntpns.org > 07/22/07 12:49:07 32583 2 1 d.ntpns.org > 07/22/07 12:50:52 32312 2 0 > 07/22/07 12:50:50 32312 2 0 > 07/22/07 12:55:02 10744 5 0 > 07/22/07 13:00:02 10060 5 0 > 07/22/07 13:05:03 9635 6 0 > 07/22/07 13:10:02 9162 7 0 > 07/22/07 13:15:02 8652 7 0 > 07/22/07 13:20:02 8260 7 0 > 07/22/07 13:25:02 7828 7 0 > 07/22/07 13:30:02 7432 7 0 > 07/22/07 13:35:02 6981 7 0 > 07/22/07 13:40:02 6623 7 0 > 07/22/07 13:45:03 6294 7 0 > 07/22/07 13:50:02 5946 7 0 > 07/22/07 13:55:02 5593 7 0 > 07/22/07 14:00:03 5292 7 0 > 07/22/07 14:05:02 5084 7 0 > 07/22/07 14:10:08 4839 7 0 > 07/22/07 14:15:02 4609 7 0 > 07/22/07 14:20:02 4392 7 0 > 07/22/07 14:25:02 4203 7 0 > 07/22/07 14:30:03 4049 7 0 > 07/22/07 14:35:03 3893 7 0 > 07/22/07 14:40:02 3749 7 0 > 07/22/07 14:45:03 3622 7 0 > 07/22/07 14:50:02 3497 7 0 > 07/22/07 14:55:04 3354 7 0 > 07/22/07 15:00:02 3192 7 0 > 07/22/07 15:05:02 2896 7 0 > 07/22/07 15:10:02 2547 7 0 > 07/22/07 15:15:02 2240 7 0 > 07/22/07 15:20:03 1912 7 0 > 07/22/07 15:25:02 1569 7 0 > 07/22/07 15:30:02 1201 7 0 > > For 6 hours the server was effectively paralysed. I also drop the connections > from these netblocks at the firewall but that does not stop them sending > requests. > > Rob Oats > UK > > _______________________________________________ > timekeepers mailing list > [email protected] > https://fortytwo.ch/mailman/cgi-bin/listinfo/timekeepers > _______________________________________________ timekeepers mailing list [email protected] https://fortytwo.ch/mailman/cgi-bin/listinfo/timekeepers
