Hi Jeroen
Did you check if the customer's network is maybe infected with some botnet or spambot that triggers honeypots?
Usually we learn about such incidents through GovCert or other complaints. We received none.
Clearly, if the IP changes and the customer gets blocked again, it is something being caused by the source IP...
Netflow... Netflow all the things ;)
We only have traffic counters, no detailed netflows :-)
The counters look normal. About 10:1 download:upload ratio, and similar to other customers.
Mit freundlichen Grüssen
-Benoît Panizzon-