Re: [fw-wiz] Acqusition of time

From: Kevin Steves (stevesk@pobox.com)
Date: 01/31/03


From: Kevin Steves <stevesk@pobox.com>
To: Ben Nagy <ben@iagu.net>
Date: Fri Jan 31 07:59:03 2003

On Thu, Jan 30, 2003 at 09:24:00AM +0100, Ben Nagy wrote:
> I could maybe be convinced that the "best" behaviour would be to start
> marking log entries somehow as soon as NTP sync got lost or the correction
> was larger than a few seconds, but I'm not sure it's anywhere near as
> serious as losing logging ability. (That said, how many people use PIXes
> that log via standard, lossy, syslog ? ;)

PIX will block if using TCP syslog and the log server dies. NTP is
fairly new in PIX and I'm not sure if it blocks if it loses NTP
peers/sync. Seems rather drastic.

Regarding logging, IOS will indicate in logs when logging with
timestamp (I think) whether time is not authoritative and if using NTP
whether it's not synched. '*' and '.' before the time as I recall.
Don't know offhand if PIX does that.

But then, if you don't log, as discussed in the recent thread that
died, it doesn't matter :)



Relevant Pages

  • Re: SNTP Question
    ... to the destination. ... PIX supports NTP ... ... Prev by Date: ...
    (comp.dcom.sys.cisco)
  • Re: PIX PDM Certificate problem
    ... Yes, works fine, server and pix use both NTP and clocks are up to date and ... If not use NTP to keep it current ...
    (comp.dcom.sys.cisco)
  • Re: f8: NetworkManager + runlevel 3 problem
    ... logging in. ... This one's in bugzilla. ... I don't know if NTP will start working when a network becomes available, ... It'd quit and stay dead if the network was a notwork, ...
    (Fedora)