NODE64 Sonar: the measurement network
Seeing measurement traffic in your logs and looking for the source? This page explains what NODE64 Sonar measures, what the traffic looks like, and how to have your systems excluded permanently.
Probes
4
Countries
1
Networks (AS)
3
Measurements (7 days)
660
One dot per country. No more precise than that – there is no GeoIP database behind it, only the country the probe reported itself.
What Sonar is
Sonar is a measurement network for reachability and latency. Devices whose operators have explicitly opted in run small network measurements – ping, traceroute, DNS queries, TLS certificate checks. The purpose is an outside view of your own infrastructure: is a service reachable from outside, how long is the path, does the nameserver answer. Sonar is explicitly not a vulnerability scanner: it does not sweep port ranges, does not attempt logins, and does not inspect content.
What the traffic looks like
The profile is narrow and does not change:
- small packets, fixed timeouts, limited hop count – no floods, no large payloads
- low frequency, with a minimum interval between recurring measurements
- layered caps per target, per probe, per account and globally – the per-target cap applies across all users
- every measurement is logged: who ordered it, which probe ran it, against which target, when, and with which profile
Where the traffic comes from
A measurement originates from the participant's own connection, not from a NODE64 data centre. You will therefore not see a NODE64 address but the address of a participant or of one of our own measurement nodes. Measurements only run against targets the requester has proven to own, or against a short, curated list of public services designed for measurement traffic.
Opting out
Want your address ranges or domains excluded permanently? Send us the networks or names concerned. We add them to the global block list; it then applies to all accounts and includes subdomains.
Please give networks in CIDR notation, or the domain. No justification needed – the request is enough.
What Sonar does not do
- no port scans and no port ranges
- no login attempts, no credentials, no content
- no measurements against internal or private address ranges
- no sharing of measurement data with third parties; storage exclusively in Germany
Master nodes of the network
Master nodes are the fixed reference points every other probe measures against. Measurement traffic may originate here.
- NODE64 Anchor DE DE · AS24940 · 0 % · IPv4
Country, network operator and operating figures are visible – never an address.
Considering using NODE64 Sonar yourself? This page explains what it does.