Troubleshooting unwanted NTP Traffic
- by Jaxaeon
A domain controller running Windows Server 2012 is sending NTP and NETBIOS traffic to an address that has never been configured as a time provider. The server logs give no indication that any NTP traffic is failing. The only place I see any evidence of this traffic is in pfSense system logs:
(Blocked) Jun 9 08:48:50 DOMAIN 10.0.1.100:123 …