Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Classification of traffic using NTP fails

Hi folks,

I have tried various settings in the firewall rules that use the hairpin NAT to provide local NTP services. The daily reports show a high count of hits on UDP 123. Occasionally the report shows a low count hit on NTP, which I suspect is from the internal NTP server checking time.

The issue is not new and has been seen in a number of previous versions of XG firmware.

So, what needs to be changed in my rules to allow correct classification of NTP or is there a fix required to XG firmware?

The current hairpin rules are using DPI, I have tried using web proxy.

Ian



This thread was automatically locked due to age.
Parents
  • Most likely the app classification is not accurate. But mine is? Maybe your traffic is different to mine. NTP is not NTP in most cases. There are different types of NTP. So based on the port, plenty attackers try to use the port 123 to communicate with there apps (C2 Communication). 

    If your NTP is not correctly pickup, you could do a wireshark dump and check the wireshark dump, if you find anything odd looking. 

    There were some issues with ThunderVPN etc. based on Port123. But not picking up NTP at all is rather new to me. 

    Check the logviewer on Port123 if there is a app classification. 

Reply
  • Most likely the app classification is not accurate. But mine is? Maybe your traffic is different to mine. NTP is not NTP in most cases. There are different types of NTP. So based on the port, plenty attackers try to use the port 123 to communicate with there apps (C2 Communication). 

    If your NTP is not correctly pickup, you could do a wireshark dump and check the wireshark dump, if you find anything odd looking. 

    There were some issues with ThunderVPN etc. based on Port123. But not picking up NTP at all is rather new to me. 

    Check the logviewer on Port123 if there is a app classification. 

Children