Hi there,
I have a customer who is getting logs on its Internet Edge firewall regarding NTP requests made from his Meraki switches. The weird thing is that some NTP requests are to the following domains/IPs between others (cloudfare i.e)
exit-relay.tor.world (178.162.211.152)
support.russianbridesnetwork.com (95.216.218.15)
formularfetischisten.de (85.10.240.253)
pauseq4vntp2.datamossa.io (103.126.53.123)
Which don´t seem to be related with an NTP service, specially the exit-relay.tor.world domain. He is very concerned about these requests.
Can you please help me to understand why Meraki switches are sending NTP requests to those domains? Is there any list with specific time server that meraki uses?
I opened a case with Meraki support but their answer so far is that "it is expected" however, I can not come back with my customer with that answer specially due the domains are being requested.
Looking forward for some help