Great Circle Associates Firewalls
(November 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: NTP through a firewall
From: sgcccdc @ citec . qld . gov . au (Colin Campbell)
Date: Wed, 15 Nov 1995 08:33:25 +1000 (EST)
To: jwilde @ westmail . com
Cc: firewalls @ greatcircle . com
In-reply-to: <9511141914 . AA06416 @ westlan . com> from "jwilde @ westmail . com" at Nov 14, 95 01:16:38 pm

My mailer thinks jwilde @
 westmail .
 com said:
> 
> I was wondering if there would be any security concerns about using my firewall 
> as an NTP Server for the rest of our network.  I was thinking of opening an udp 
> port for NTP and (network time protocol) allowing only my time provider to talk 
> to the firewall via NTP through an generalized proxy.  My question is this, 
> would this open a security hole?  Wouldn't the NTP Server (our firewall) go out 
> and get the time when it is specified?  Any comments would be appreciated.
> 

The only problem with this is the fact that NTP is UDP-based which
means anyone with the inclination can screw around with the time on
your network merely by impersonating the host you look to for the
correct time. Sure thay can only make small and gradual adjustments
but they can do it and you did ask. 

I think NTP uses the same port at either end (like DNS server to
server) so you do not need to allow "udp from host blah to host bastion
where port > 1023" which can be dangerous and is generally frowned
upon.

Colin


Follow-Ups:
References:
Indexed By Date Previous: Re: HPUX client program for OPIE/SKEY???
From: frankw @ in . net (Frank Willoughby)
Next: Re: Configuration
From: sgcccdc @ citec . qld . gov . au (Colin Campbell)
Indexed By Thread Previous: Re: NTP through a firewall
From: "Bryan D. Boyle" <bdboyle @ maverick . erenj . com>
Next: Re: NTP through a firewall
From: Thomas E Zerucha <zerucha @ shell . portal . com>

Google
 
Search Internet Search www.greatcircle.com