Great Circle Associates Firewalls
(October 1993)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Anyone want to test a UDP relayer?
From: "Louis A. Mamakos" <louie @ NI . umd . edu>
Date: Wed, 06 Oct 1993 00:45:27 -0400
To: Tom Fitzgerald <fitz @ wang . com>
Cc: firewalls @ GreatCircle . COM
In-reply-to: Your message of "Wed, 06 Oct 1993 00:10:23 EDT." <199310060410 . AA11942 @ fnord . wang . com>

While I can't take you up on your offer to test your code, since I'm
about to change jobs in a couple weeks.  As an NTP weenie, two
thoughts came to my mind:

- Is the implementation style such that the delay through the
forwarder is constant without regard to the direction of flow?  If
not, this will introduce a bias in the measured clock offsets due to
an asymmetric delay.

- Why not just run an NTP peer on the firewall system, and live
without direct NTP connectivity?  I guess there are plenty of reasons,
but I just have this (possibly unfounded) worry about yet another
source of "noise" on the NTP clock offset/delay samples being
introduced by the relay daemon.

Entering "paranoid mode"..

Also, having a "secured" NTP daemon on the firewall lets you configure
authenticated NTP peers, and you won't have to replicate all of that
on your "internal" machines.  This could be important, as you may not
want to be open to someone spoofing an (unauthenticated) external NTP
clock peer and screwing with your system's time.  This can be an issue
for protocols (e.g., Kerberos) which use timestamps in protocol
exchanges to protect against replay attacks.

Louis Mamakos
University of Maryland




Follow-Ups:
References:
Indexed By Date Previous: Anyone want to test a UDP relayer?
From: Tom Fitzgerald <fitz @ wang . com>
Next: Re: Security related patches
From: ellozy @ farber . harvard . edu (Mohamed Ellozy)
Indexed By Thread Previous: Anyone want to test a UDP relayer?
From: Tom Fitzgerald <fitz @ wang . com>
Next: Re: Anyone want to test a UDP relayer?
From: Tom Fitzgerald <fitz @ wang . com>

Google
 
Search Internet Search www.greatcircle.com