Re: [fw-wiz] Acqusition of time

From: Volker Tanger (volker.tanger@discon.de)
Date: 01/29/03


From: Volker Tanger <volker.tanger@discon.de>
To: Brian Monkman <bmonkman@comcast.net>
Date: Wed Jan 29 12:13:35 2003

Greetings!

Brian Monkman wrote:
>
> We are talking about a firewall farm. [...] central logging server.
[...]
> In your opinion - should we have a battery backed-up clock on these
> firewalls or is the network time source sufficient?

Do both - the battery back-up for having an approximately accurate time
in case of rebooting during problems with the external time source.
Network problems are more probable than attacks against radio or GPS
clocks here.

But for a real sync between the servers you need them to synchronize
onto the same source - be it via network (same, preferrably internal NTP
server) or via the same external source (radio clock or GPS clock).

Bye

Volker Tanger
IT-Security Consulting

-- 
discon gmbh
Wrangelstraße 100
D-10997 Berlin
fon    +49 30 6104-3307
fax    +49 30 6104-3461
volker.tanger@discon.de
http://www.discon.de/


Relevant Pages

  • Re: Ancient G3 - time server never automatically updates
    ... server. ... system clock and the server clock. ... I don't know if your system uses the same battery (someone at the Genius Bar told me Apple standardized on the LS14250 3.6V Lithium 1/2 AA for all their systems. ... Has the OP replaced the original battery? ...
    (comp.sys.mac.system)
  • Re: Windows server sync to LocalCLK
    ... Now I have a linux box that tries to sync with this xp box but it doesn't work for at least 5 minutes of the NTP service starting. ... I've searched around and people are saying that it takes about 5-8 minutes before the server trusts the local clock as the source. ... one clock is selected more or less at random to act as the time source for the herd. ...
    (comp.protocols.time.ntp)
  • Re: Does time run off the mains frequency (very strange behaviour)
    ... > setup MS Small busines server 2000 running on a HP server ... > platformin network with XP ... > would have used the internal quartz clock on the motherboard for time. ... (e.g. by an external time source). ...
    (microsoft.public.windows.server.general)
  • Re: Testing NTP server
    ... XType 1 is an undisciplined local ... no good time source, set the clock on the NTP server manually, then ...
    (comp.unix.solaris)
  • clock syncro
    ... I noticed my clock getting very slow, losing a hour or so per day, so I ... I put a new battery in thinking that was the ... server. ...
    (microsoft.public.windowsxp.general)