Great Circle Associates Firewalls
(January 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Time Synchronization thru firewall
From: criney1 @ abacus . tis . tandy . com (Chris Riney)
Date: Fri, 13 Jan 1995 10:13:36 -0600 (CST)
To: brian @ mn . chey . com (Brian Smith)
Cc: Firewalls @ GreatCircle . COM
In-reply-to: <9501131508.AA00264@ mn.chey.com> from "Brian Smith" at Jan 13, 95 09:05:20 am

> 
> Does anyone have recommendations regarding how to receive time synchronization
> through a firewall?  Is there a preferred protocol to use and available
> software?  Is there a well established/trusted host on the Internet
> (e.g. NIST labs) that provides a "heartbeat"?
> 
> I'd appreciate direct email replies, as I do not monitor this list.
> 
> Many Thanks,
> Brian Smith
> brian @
 mn .
 chey .
 com
> 

A number of OS vendors provide a version of NTPD (Network Time Protocol Daemon)
with their package.  For those that don't, or if you want a newer version
there is xntpd version 3.3m (I got our copy from louie.udel.edu:/pub/ntp)

One way to configure a time service interface is to have the Gateway/bastion
host quiry a reliable ntp server, which in turn allows systems on your side
to quiry it.  The ntp configuration includes configuring who is allowed
to quiry the server, along with access codes.

Several of the Service providers (like PSI whom we contract with currently)
provide ntp level 1 servers, some of which are in turn sync'd with the
US Navigational Satalite system (forgot it's name right now).  If in doubt
ask your service provider if they provide this service, or whom they would
recommend.

I would not recommend using timed, since you have no control over who
is the master, or can become your master server. Timed is also a UDP
broadcast service, that is transmited on a consistent repetivity.

==========================================================================
Chris Riney                     E-mail: chris .
 riney @
 tandy .
 com 
Tandy Information Services             
Tandy Technology Sqr, Suite 200
Fort Worth, TX 76102             Phone: 817/878-0308; 8:00am-5:00pm CST,Mo-Fr



Follow-Ups:
References:
Indexed By Date Previous: Re: List of firewall log attack signatures?
From: gordy @ nytimes . com (Gordy Thompson)
Next: Firewalls and SUN systems
From: sdwix @ ttd . sandia . gov (Steven D. Wix)
Indexed By Thread Previous: Time Synchronization thru firewall
From: Brian Smith <brian @ mn . chey . com>
Next: Re: Time Synchronization thru firewall
From: "Simon J. Gerraty" <sjg @ zen . void . oz . au>

Google
 
Search Internet Search www.greatcircle.com