Hello,
In UTM 9 i was able to point Sophos at a time source, and then internal clients could reference it for time. I don't see this option in XG, is this no longer possible?
Thanks!
This thread was automatically locked due to age.
I simply DNAT NTP Traffic from my old UTM interface(IP) to my DC and use the NTP server of my DC.
My DC is the only source, which can use NTP.
As simple as that is a workaround.
UTM NTP Server is quite simple. It simply stores the time. So basically no security benefits at all.
LuCar Toni said:UTM NTP Server is quite simple. It simply stores the time. So basically no security benefits at all.
Not quite true, because you could point your internal devices at it either individually or via network object. Also you could set which NTP services it accessed, you could test the servers to see which were failing/accurate.
Ian
I am not sure, what you mean.
If i redirect everything to my DC / NTP Server in my network, i can use this NTP Server with more possibilities as UTM can do right now.
Or maybe i miss your point?
NTP Server (and which should i use) are sometimes a real issue.
Some devices are not using the DNS/DHCP Server, so they will try to reach the Internet pool and fails sometimes.
There is another limitation of not being able to create DNAT rules from LAN to WAN like in UTM.
But this is addressed, as far as i know, with future releases.
And again, this is just a UTM workaround for addressing another issue. If XG had a NTP server / proxy right now, it would not help for this issue at all.
PS: I do not want to argue with you at all. I would like to see a NTP server in XG as well. But i do not think, this is the right solution right now for this point. You would need a transparent NTP proxy, not a NTP server.
Hello Lucar Toni
I assume your DCs are Windows. In that case, many devices will not use Windows as NTP. It is well known Windows' NTP is a "Windows" NTP only, and nothing else. It is not a full featured universal NTP. Many devices will not talk to Windows as NTP source, namely hardware devices like switches and bare metal server's UEFI (or BIOS). For example, IBM's Storwise was incompatible with Windos NTP.
Some reading: support.ntp.org/.../WindowsTimeService
What I foresee for XG is at least NTP relay "without rules". Leaving managing NTP pools and firewall rules entirely to XG.
Paul Jr