Great Circle Associates Firewalls
(December 1992)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Notes from Firewalls BOF at USENIX LISA Conference
From: Brent Chapman <brent @ GreatCircle . COM>
Date: Thu, 03 Dec 92 19:44:56 -0800
To: Firewalls @ GreatCircle . COM
In-reply-to: Your message of Thu, 03 Dec 92 11:39:21 EST

Steve Bellovin <smb @
 research .
 att .
 com> writes:

# 	 I haven't looked at NTP yet; none of the clients I've set up firewalls
# 	 for have requested it.  If it uses a random port for one end of the
# 	 connection, I don't see any safe way to let NTP traffic through a
# 	 firewall that only looks at destination addresses; if you do, you'll
# 	 also end up exposing all RPC-based services, like YP and so forth.
# 
# The essential use of ntp -- keeping time synchronization -- uses port 123
# on both ends.  But other uses -- queries to remote time servers, or
# forcing the right time when rebooting -- use random inside ports.

Then we should be able to deal with NTP the same way we deal with DNS:
allow server-to-server connections, and to hell with client-to-server
connections across the filtering wall.  There are good reasons that
you might want to do client-to-server DNS connections across a filtering
wall (using "nslookup" or "dig" to try to track down how your server
is getting bogus data from another server on the other side of the
filter, for instance), but I don't know if that's such an issue for NTP.


-Brent
--
Brent Chapman                                   Great Circle Associates
Brent @
 GreatCircle .
 COM                           1057 West Dana Street
+1 415 962 0841                                 Mountain View, CA  94041



Indexed By Date Previous: Re: packet filter metalanguage
From: Brent Chapman <brent @ GreatCircle . COM>
Next: on breaking firewalls
From: tep @ tots . Logicon . COM
Indexed By Thread Previous: Re: Notes from Firewalls BOF at USENIX LISA Conference
From: smb @ research . att . com
Next: Re: Notes from Firewalls BOF at USENIX LISA Conference
From: butterback @ mc . com (Brian Utterback)

Google
 
Search Internet Search www.greatcircle.com