Re: NTP over several firewalls

From: Richard H Miller (rick_at_bcm.tmc.edu)
Date: 09/09/03


Date: 9 Sep 2003 19:34:58 GMT

nebula (donotemailme@nowhere.com) wrote:
: Hi all,

: I have a question that creates a continious discussion in our organisation
: and I would like to hear your view on it.

: We have a network looking like:

: Internet --> firewall --> DMZ -- firewall2 --> backend --> firewall 3

: --> internal network.

: Each network is divided in several vlans. What I offer to do for NTP is as
: follows:

: Place a NTP server on the internal network, backend and dmz

: Let synchronization goes as follows: dmz ntp server --> backend ntp
: server --> internal ntp server. Let all hosts in a network sync with their
: network ntp server. So DMZ hosts to DMZ ntp and so on. One

: exception: Routers on the internet will sync to the DMZ NTP server too.

: Now, one of my co-workers wants the hosts to sync their time with the
: firewalls, so we do not need to deploy these servers (except for one which
: will have the atom clock connected to it). Personally I find that
: connections directed to the firewall should be limited to management of
: authentication connections. How do you guys/girls see this?

You are correct. Your design is appropriate [you may wish to cut down on the
number of timeserver by placing one in the DMZ and an internal one setting up the rules to
allow all of your systems to NTP to them and the internal NTP servers would only sync with
the DMZ server and the DMZ server is the only device to do NTP to the internet.

You actually want your firewalls [if possible] to sync to the internal DMZ server. [This would
be the one exception to not running services on the firewalls; you need to do this for any
type of log sync or correlation with other events].

Servers *should not* time sync with the firewalls. You are correct that the only connections
directed to the firewall should be for its care and feeding.

rick

Richard H. Miller, MCSE, CCSE
Information Security Manager
Information Technology Security and Compliance
Information Technology - Baylor College of Medicine



Relevant Pages

  • Re: Time sync
    ... > Just want to sync current server time with some internet atomic ... a ntp server. ... and only sync from stratum 2 or higher numbers... ...
    (freebsd-newbies)
  • Re: W32time - Synchronisation funktioniert nicht automatisch
    ... In meiner DMZ Umgebung habe ... Server machen kann. ... kann ich einen Windows 2000 Server auch NTP Server ... funktioniert die manuelle Synchronisation trotzdem ...
    (microsoft.public.de.german.win2000.sonstiges)
  • Re: ntpdate: no server suitable for synchronization found
    ... that the t2000 cannot act as a server if it isn't sync. ... so i use a t2000 as a ntp server, and test it from a ultra 20: ... As you can see, the ultra 20 receives the correct date, but the date ...
    (SunManagers)
  • Re: Time Sync Not Working
    ... I tried the NTP server you recommended and I still get an error saying an ... error occurred while trying to sync with the server. ...
    (microsoft.public.windowsxp.general)
  • Re: How to Configure Redundant NTP server in Solaris
    ... > I have Configure NTP server and I want to have one more NTP server for ... > my NTP client, so that if one NTP server went down the client should ... > sync its time from another server. ...
    (comp.unix.solaris)