Re: ntpd on a NAT gateway seems to do nothing



On 2007-Jul-24 16:00:08 +0100, Pete French <petefrench@xxxxxxxxxxxxxxxx> wrote:
at least I cannot see anything wrong). I would assume that ntpdate
also uses UDP - and using that I can see all these servers ?

Yes it does. The major difference is that ntpd will use a source
port of 123 whilst ntpdate will use a dynamic source port.

Is it possible that your NAT rules are interfering with ntpd using
port 123? Can you check that ntpd is binding to port 123 (using
lsof or netstat+fstat). As well as tcpdump'ing the NTP traffic,
you might like to ktrace ntpd and verify that incoming packets
are actually arriving there.

If your NAT box is not busy, you might be able to enable logging on
som relevant rules and see what your firewall is actually doing
with the packets.

--
Peter Jeremy

Attachment: pgpepGoby2wim.pgp
Description: PGP signature



Relevant Pages

  • Re: Multiple ntp processes?
    ... What is really strange is the same script, same rc3.d setup and the old version had 2 ntpd processes running...now with the new version fixed the problem. ... Oct 16 01:30:36 adminserver sshd: Failed password for invalid user tester from 210.17.215.224 port 49310 ssh2 ...
    (comp.protocols.time.ntp)
  • Re: Multiple ntp processes?
    ... What is really strange is the same script, same rc3.d setup and the old version had 2 ntpd processes running...now with the new version fixed the problem. ... Oct 16 01:30:36 adminserver sshd: Failed password for invalid user tester from 210.17.215.224 port 49310 ssh2 ...
    (comp.protocols.time.ntp)
  • Re: ntpd as broadcastclient - not working?
    ... the proper way of debugging these problems is to run ntpd ... >>Port 123 is the proper port for broadcast, ... Danny, I had run CVSup on FreeBSD, and it didn't update anything. ... spinning our wheels trying to get broadcastclient to work. ...
    (freebsd-questions)
  • Re: ntpd wont sync
    ... You may not have a local firewall, but your ISP may have one between ... however I'm not definitely 100% sure that the port ... ask them if they are blocking 123/UDP and if they have a time server ... start ntpd and use a web-based tool to attempt to contact your ntpd: ...
    (comp.protocols.time.ntp)
  • Re: My ntpd stopped working
    ... It appears that your server is "in the red" most of ... connections/packets on that port. ... Are you sure that your firewall is not blocking port 123/UDP? ... Are you sure that ntpd is not using another configuration file? ...
    (comp.protocols.time.ntp)