Great Circle Associates Firewalls
(April 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: xntpd and gauntlet 3.2
From: Bill Husler <bhusler @ community . net>
Date: Tue, 8 Apr 97 06:46:12 -0700
To: "Arley Carter" <ac @ twinds . com>
Cc: "firewalls(a)greatcircle.com" <firewalls @ GreatCircle . COM>

>On Fri, 4 Apr 1997, Arley Carter wrote:
>
>> On Fri, 4 Apr 1997 DSAWYER @
 PILLSBURY .
 COM wrote:
>>
>> >      In a nutshell what I need to know is how do I get udp based packets 
on
>> >      port 123 through the firewall?
>> > 
>> >      Anybody have any ideas?
>>
>> Bad Idea.  Setup the firewall to be the auhtoritative time source for the 
>> domain using xntpd to the outside world.  Set the firewall to broadcast time
>> to the networks you want.  Have the inside machines listen to time 
>> broadcasts from the firewall.  No need to pass udp through the firewall.
>
>Agreed.  If you're super-paranoid, then you can shell out the US$200 for a
>GPS receiver and make yourself into a stratum-1 server.  (If you do this,
>you should do it outside the firewall, offer stratum-1 services to others,
>and make your firewall a stratum-2 server, using ntp's builtin
>cryptographic authentication.) 
>
>And to whoever said that you shouldn't use time-based cryptography, there
>are well-respected cryptosystems which rely on accurate time info on both
>client and server to eliminate replay attacks and other time-based hacks.
>To dismiss them merely because they require accurate time info is silly.
>
>__
>Todd Graham Lewis          MindSpring Enterprises      tlewis @
 mindspring .
 com
>
>
Does anyone have a reference for where to get this US$200 GPS NTP server? 
The Ads I've seen are for 10 times that amount.
Bill

Please remember to always flame via private eMail - the rest of the group 
is just not interested.


Indexed By Date Previous: Re: virus scanning
From: drexx @ sunphil . mozcom . com (Drexx Laggui)
Next: FTP Software's Secure Client
From: "dennis keller" <dennis_keller @ smtp . ddre . dla . mil>
Indexed By Thread Previous: Re: xntpd and gauntlet 3.2
From: "Jonathan M. Bresler" <jmb @ FRB . GOV>
Next: Re: Frame Relay
From: Vern Williams <logicon @ flash . net>

Google
 
Search Internet Search www.greatcircle.com