So I'm making progress but no dice yet!
I moved the IPs to a unit on the QFX link MX side.
run show arp no-resolve | match 123.123.123.123
46:ff:be:f7:ef:1c 123.123.123.123 ae1.647 none
I'm getting an ARP entry now.
I'm seeing the counter rise as well
Counters:
Name Bytes Packets
NTP-HIJACK 1648931 21703
However if i try to do something like ntpdate -qu 8.8.8.8 I still get a no server message so its still not forwarding to the IP but its being filtered? Whats the next step.
I'm using 8.8.8.8 as a "random ip that i know does not have NTP setup"
Actually i just did a commit confirm on the following
set firewall family inet filter FLTR-IN term 5-T-NTP-HIJACK from destination-address 8.8.8.8/32
set firewall family inet filter FLTR-IN term 5-T-NTP-HIJACK from destination-port 123
set firewall family inet filter FLTR-IN term 5-T-NTP-HIJACK then count NTP-HIJACK
set firewall family inet filter FLTR-IN term 5-T-NTP-HIJACK then next-ip 123.123.123.123/32
I'm still returning the following:
[root@localhost~]# ntpdate -qu 8.8.8.8
server 8.8.8.8, stratum 0, offset 0.000000, delay 0.00000
24 Jul 08:07:22 ntpdate[96741]: no server suitable for synchronization found
So i'm convinced its just not working at all even when i specify destination address and port.
Currently it seems all this filter is doing is rejecting any ntp traffic and not really changing the destination address at all.