Re: Firewalled NTP on Redhat - ntpdate works, but ntpq doesn't



Young, Mike wrote:
Hello,

I'm seeing an odd NTP problem on a couple of Redhat servers here.
Basically the NTP client is on a firewalled DMZ, away from the NTP server.
NTP updates via ntpq work fine on the local NTP server subnet, but it
isn't working for hosts on the firewalled DMZ. We've checked ports on the
firewall, and 123/UDP is open. In addition, we see packets incrementing
when we use the "iostat" command in ntpdc, and don't see any dropped or
ignored packets in iostat either.

Any ideas?

Does the firewall allow port 123 in _both_ directions? NTP requires unrestricted access to 123/udp for _both_ source and destination.

Thanks,
Mike.



--
Stephen Carville <stephen@xxxxxxxxxxxxxx>
Systems Engineer
Land America
1.626.667.1450 X326

--
redhat-list mailing list
unsubscribe mailto:redhat-list-request@xxxxxxxxxx?subject=unsubscribe
https://www.redhat.com/mailman/listinfo/redhat-list



Relevant Pages

  • Re: broadcast client
    ... synchronizing with the same ntp server. ... ntp displined clock. ... because the drift discipline is inversely ... The reason for the backup to long poll intervals is ...
    (comp.protocols.time.ntp)
  • Re: Local (own site) NTP servers.
    ... been messing about trying to get a local GPS ... Disciplined NTP server working, ... to be able to take PPS based GPS signals, and act as a server. ... GPSDNTP server for a small low traffic LAN?.. ...
    (comp.protocols.time.ntp)
  • Re: NTPD concurrent clients limit
    ... I use my own Symmetricom gps disciplined ntp servers, my own Datum/Symmetricom gps disciplined rubidium standards for 1PPP and 10 MHz all using HP/Symmetricom gps antennas and gps splitters. ... I also run the latest release of ntpd software on several HP/Compaq Servers. ... Is this packet also implemented in a "canned" or hardware only ntp server? ... NTP is designed to work with poll intervals between 64 seconds and 1024 ...
    (comp.protocols.time.ntp)
  • Re: NTPD concurrent clients limit
    ... After some discussion with my friends here, a further defense was implemented with result the KoD time returned reveals no influence of the server. ... After learning of this "kod" packet and since these servers vend time to my applications, I would prefer or need the correct time even if something went haywire banging the fool out of a server. ... I have read articles about ntp abuse like that series of cheap routers that had an ip embedded in the firmware that was banging I believe the ucar.edu ntp servers. ... Considering how adaptive the ntpd software has to be, I'm sure it's a delicate balancing act to make it serve the whole of the time community. ...
    (comp.protocols.time.ntp)
  • Re: ntpdate synchronization b/w two ntpservers
    ... the problem is that our servers are unable to synchronize with our ntp ... ntpdate uses port 123 UDP to connect to ntp Server ... firewall for randomn ports. ...
    (comp.sys.sun.admin)