NODE64 Sonar: the measurement network

Seeing measurement traffic in your logs and looking for the source? This page explains what NODE64 Sonar measures, what the traffic looks like, and how to have your systems excluded permanently.

Probes

4

Countries

1

Networks (AS)

3

Measurements (7 days)

660

DE: 2 probes · 1 master node · 50 % reliable · centre of the country – not an exact placeDE: 1 probe · AS57575 · 100 % reliable · location given by the operatorDE: 1 probe · AS3209 · 96 % reliable · location given by the operator

One dot per country. No more precise than that – there is no GeoIP database behind it, only the country the probe reported itself.

What Sonar is

Sonar is a measurement network for reachability and latency. Devices whose operators have explicitly opted in run small network measurements – ping, traceroute, DNS queries, TLS certificate checks. The purpose is an outside view of your own infrastructure: is a service reachable from outside, how long is the path, does the nameserver answer. Sonar is explicitly not a vulnerability scanner: it does not sweep port ranges, does not attempt logins, and does not inspect content.

What the traffic looks like

The profile is narrow and does not change:

  • small packets, fixed timeouts, limited hop count – no floods, no large payloads
  • low frequency, with a minimum interval between recurring measurements
  • layered caps per target, per probe, per account and globally – the per-target cap applies across all users
  • every measurement is logged: who ordered it, which probe ran it, against which target, when, and with which profile

Where the traffic comes from

A measurement originates from the participant's own connection, not from a NODE64 data centre. You will therefore not see a NODE64 address but the address of a participant or of one of our own measurement nodes. Measurements only run against targets the requester has proven to own, or against a short, curated list of public services designed for measurement traffic.

Opting out

Want your address ranges or domains excluded permanently? Send us the networks or names concerned. We add them to the global block list; it then applies to all accounts and includes subdomains.

abuse@node64.de

Please give networks in CIDR notation, or the domain. No justification needed – the request is enough.

What Sonar does not do

  • no port scans and no port ranges
  • no login attempts, no credentials, no content
  • no measurements against internal or private address ranges
  • no sharing of measurement data with third parties; storage exclusively in Germany

Master nodes of the network

Master nodes are the fixed reference points every other probe measures against. Measurement traffic may originate here.

  • NODE64 Anchor DE DE · AS24940 · 0 % · IPv4

Country, network operator and operating figures are visible – never an address.

Considering using NODE64 Sonar yourself? This page explains what it does.