Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Classification of traffic using NTP fails

Hi folks,

I have tried various settings in the firewall rules that use the hairpin NAT to provide local NTP services. The daily reports show a high count of hits on UDP 123. Occasionally the report shows a low count hit on NTP, which I suspect is from the internal NTP server checking time.

The issue is not new and has been seen in a number of previous versions of XG firmware.

So, what needs to be changed in my rules to allow correct classification of NTP or is there a fix required to XG firmware?

The current hairpin rules are using DPI, I have tried using web proxy.

Ian



This thread was automatically locked due to age.
Parents Reply
  • Hi,

    I have tried to refine tcpdump previously only to find that the tcpdump on the XG115w has a very limited parameter range. The console port will timeout and probably kill the sessions. I will try again later today.

    I have sent you a PM with the ntpv4 capture, I have not been able to capture any ntpv3 traffic becasue the device updates its time at random intervals.

    Ian

Children