Great Circle Associates Firewalls
(July 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: need suggestion xntpd a security hole ???
From: Douglas McNaught <doug @ ono . tc . net>
Date: 05 Jul 1997 12:01:41 -0400
To: Dave Wreski <dave @ nic . com>
Cc: Bret Watson <Bret . Watson @ bwa . net>, firewalls @ GreatCircle . COM
In-reply-to: Dave Wreski's message of Sat, 5 Jul 1997 02:07:44 -0400 (EDT)
References: <Pine . GSO . 3 . 95q . 970705020432 . 8880Q-100000 @ nic . com>

Dave Wreski <dave @
 nic .
 com> writes:

> I would also like to bring ntp into my network, on the only line providing
> Internet access to a small company I'm working with.
> 
> Wouldn't the plug-gw be used in this circumstance?  Would it be advisable
> to set up a xntpd server on one of my external boxes, and use it to serve
> the internal network, consisting of about 10 machines?  Or would it be
> better to have each configure to use a proxying ntpdate?

NTP is a UDP-based service, so you can't plug-gw it.  The usual
procedure is to run an NTP daemon on the bastion host, and sync it to
as many low-stratum servers as possible.  Have the internal clients
sync either directly to the bastion host or to internal higher-stratum
servers.

-Doug
-- 
sub g{my$i=index$t,$_[0];($i%5,int$i/5)}sub h{substr$t,5*$_[1]+$_[0],1}sub n{(
$_[0]+4)%5}$t='encryptabdfghjklmoqsuvwxz';$c='fxmdwbcmagnyubnyquohyhny';while(
$c=~s/(.)(.)//){($w,$x)=g$1;($y,$z)=g$2;$w==$y&&($p.=h($w,n$x).h($y,n$z))or$x==
$z&&($p.=h(n$w,$x).h(n$y,$z))or($p.=h($y,$x).h($w,$z))}$p=~y/x/ /;print$p,"\n";


Follow-Ups:
References:
Indexed By Date Previous: Any NAT implement?
From: "Cai Xuewu" <xwcai @ mx1 . sh . cei . go . cn>
Next: Re: need suggestion xntpd a security hole ???
From: Dave Wreski <dave @ nic . com>
Indexed By Thread Previous: Re: need suggestion xntpd a security hole ???
From: Dave Wreski <dave @ nic . com>
Next: Re: need suggestion xntpd a security hole ???
From: Dave Wreski <dave @ nic . com>

Google
 
Search Internet Search www.greatcircle.com