Great Circle Associates Firewalls
(May 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: NTP on a bastion system
From: nto2584 @ tserver . dsac . dla . mil (Steven Payne)
Date: Tue, 16 May 1995 15:04:59 -0400 (EDT)
To: mjr @ tis . com (Marcus J. Ranum)
Cc: firewalls @ greatcircle . com
In-reply-to: <3920 . 9505161300 @ illuminati> from "Marcus J. Ranum" at May 16, 95 09:00:36 am

> 
> >Has anynone knowed and experienced about some tools that
> >relay traffic back and forth between two NTP servers.
> >They must run on a bastion system (FWTK,SunOS4.1.4).
> 
> 	Ntpd is pretty good for the job. :)
> 
> 	Firewalls make good network clocks, especially if you have
> more than one of them. Just have the firewall sync with a timesource
> outside, and have inside systems get clocking from the firewall and
> spread it internally.
> 
> mjr.
> 

We are using the xntpd among the two hosts on our class C with the firewall
acting as a server to both hostsi, the router allows the firewall access to
our class C net, so we needed to use the firewall as a server.  The firewall
itself is using the kerberos master server as the xntpd master server.  It is
absolutely essential for the system clocks to be in sync for kerberos to 
operate.  If not then the tickets issued will be out of sync and not operate
or better yet expire (at least for 5 minute root instance tickets).

Marcus is right they make good clocks. We are using the xntpd in just the
fashion that marcus describes.

steve payne
spayne @
 dsac .
 dla .
 mil
comm 614-692-9991


References:
Indexed By Date Previous: Firewall performance from neal nelson RTE
From: nto2584 @ tserver . dsac . dla . mil (Steven Payne)
Next: Re: Firewall performance from neal nelson RTE
From: nall @ zilker . net (Joe Nall)
Indexed By Thread Previous: Re: NTP on a bastion system
From: "Marcus J. Ranum" <mjr @ tis . com>
Next: NTP on a bastion system
From: Tom Fitzgerald <fitz @ wang . com>

Google
 
Search Internet Search www.greatcircle.com