<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NTP Rule is bidirectional ? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ntp-rule-is-bidirectional/m-p/4729487#M1095468</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;do you mean the traffic (port 123) is ntp server to client ? do you mean we don't need to allow client to server traffic ( port 123 ) ?&lt;/P&gt;</description>
    <pubDate>Tue, 29 Nov 2022 05:42:31 GMT</pubDate>
    <dc:creator>MrBeginner</dc:creator>
    <dc:date>2022-11-29T05:42:31Z</dc:date>
    <item>
      <title>NTP Rule is bidirectional ?</title>
      <link>https://community.cisco.com/t5/network-security/ntp-rule-is-bidirectional/m-p/4725987#M1095231</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I confuse how to work NTP traffic. My network device need NTP from window server. the firewall is between my network device and Window server .I enable NTP server service on window.&lt;/P&gt;&lt;P&gt;So i would like to know If i open NTP port 123 on firewall for the traffic from my network device to window server&amp;nbsp; ?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 15:38:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-rule-is-bidirectional/m-p/4725987#M1095231</guid>
      <dc:creator>MrBeginner</dc:creator>
      <dc:date>2022-11-22T15:38:29Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Rule is bidirectional ?</title>
      <link>https://community.cisco.com/t5/network-security/ntp-rule-is-bidirectional/m-p/4725989#M1095233</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/823684"&gt;@MrBeginner&lt;/a&gt; you'd create a rule from source of the network device to the destination of the ntp server on udp/123. As the firewall is stateful the return traffic should be permitted.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 15:43:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-rule-is-bidirectional/m-p/4725989#M1095233</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-11-22T15:43:20Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Rule is bidirectional ?</title>
      <link>https://community.cisco.com/t5/network-security/ntp-rule-is-bidirectional/m-p/4725990#M1095234</link>
      <description>&lt;P&gt;In most situations (which includes yours) the network device is the NTP-client and queries the NTP-server. So, yes, you open the port UDP/123 from device to the server.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 15:44:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-rule-is-bidirectional/m-p/4725990#M1095234</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2022-11-22T15:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Rule is bidirectional ?</title>
      <link>https://community.cisco.com/t5/network-security/ntp-rule-is-bidirectional/m-p/4726360#M1095264</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Thanks. Let me know if i am using window as ntp server,cisco network can get time sync ? it is any limitation ? Because I worry network device didn't understand SNTP or window only SNTP protocol.&lt;/P&gt;&lt;P&gt;if i want to do my router device get ntp for NTP server and other network devices will get ntp from my router, what kind of additional configuration do i need to configure on my router ?&lt;/P&gt;&lt;P&gt;what kind of security configuration can do on my router ?&amp;nbsp; any advantage will have if i use ntp soure as loopback ?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 07:13:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-rule-is-bidirectional/m-p/4726360#M1095264</guid>
      <dc:creator>MrBeginner</dc:creator>
      <dc:date>2022-11-23T07:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Rule is bidirectional ?</title>
      <link>https://community.cisco.com/t5/network-security/ntp-rule-is-bidirectional/m-p/4726411#M1095269</link>
      <description>&lt;P&gt;It depends on the Cisco device if they do NTP or SNTP. And also if they only implement an NTP client or an NTP server.&lt;/P&gt;
&lt;P&gt;Assuming that your Windows Server has a correct time, I would point all network devices to this server. The typical command is&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;ntp server IPADDRESS&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 09:12:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-rule-is-bidirectional/m-p/4726411#M1095269</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2022-11-23T09:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Rule is bidirectional ?</title>
      <link>https://community.cisco.com/t5/network-security/ntp-rule-is-bidirectional/m-p/4728289#M1095379</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/325766"&gt;@Karsten Iwen&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I only want the to allow on router to access to NTP server and the rest network device want to get NTP from router. It is possible ?&lt;/P&gt;&lt;P&gt;what kind of configuration do i need on my router ? Peer command ?&lt;/P&gt;</description>
      <pubDate>Sat, 26 Nov 2022 02:22:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-rule-is-bidirectional/m-p/4728289#M1095379</guid>
      <dc:creator>MrBeginner</dc:creator>
      <dc:date>2022-11-26T02:22:38Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Rule is bidirectional ?</title>
      <link>https://community.cisco.com/t5/network-security/ntp-rule-is-bidirectional/m-p/4728312#M1095381</link>
      <description>&lt;P&gt;should be fairly straight forward, by default router works in NTP client as well as server mode, it means it can get NTP info from external source as client, as well be a NTP server for other devices.&lt;/P&gt;
&lt;P&gt;so on upstream router just configure the router with ntp server with command&lt;/P&gt;
&lt;P&gt;ntp server &amp;lt;IP of NTP server&amp;gt;&lt;/P&gt;
&lt;P&gt;if the server supports authentication then configure authentication as well.&lt;/P&gt;
&lt;P&gt;on downstream devices, just point to upstream router as NTP server (same command)&lt;/P&gt;
&lt;P&gt;show ntp association to verify, play close attention to reference clock, you will see the reference clock on downstream devices/routers will be upstream router IP and for upstream router, it will be the NTP server you configured.&lt;/P&gt;
&lt;P&gt;example upstream&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ammahend_0-1669431965225.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/169109i134F0B73BCA29939/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ammahend_0-1669431965225.png" alt="ammahend_0-1669431965225.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;downstream&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ammahend_2-1669432060762.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/169111i35C2BBE481291BFB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ammahend_2-1669432060762.png" alt="ammahend_2-1669432060762.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 26 Nov 2022 03:07:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-rule-is-bidirectional/m-p/4728312#M1095381</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2022-11-26T03:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Rule is bidirectional ?</title>
      <link>https://community.cisco.com/t5/network-security/ntp-rule-is-bidirectional/m-p/4728351#M1095382</link>
      <description>&lt;P&gt;As already explained, it will work straight out of the box as a server if the router already got the time via NTP. The peer functionality is a different way to synchronise the time between different devices. Make also sure that the other devices can reach the router on UDP/123 and this is not blocked by any router ACL.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Nov 2022 07:41:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-rule-is-bidirectional/m-p/4728351#M1095382</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2022-11-26T07:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Rule is bidirectional ?</title>
      <link>https://community.cisco.com/t5/network-security/ntp-rule-is-bidirectional/m-p/4729369#M1095460</link>
      <description>&lt;P&gt;I do lab,&amp;nbsp;&lt;BR /&gt;NTP Server-inside-FW-outside-NTP client&amp;nbsp;&lt;BR /&gt;for FW to allow NTP traffic to pass through you need access-list in OUT direction in&amp;nbsp;&lt;BR /&gt;the access-list is eq ntp.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I do lab and test it and client is sync with server inside.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2022 21:28:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-rule-is-bidirectional/m-p/4729369#M1095460</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-11-28T21:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Rule is bidirectional ?</title>
      <link>https://community.cisco.com/t5/network-security/ntp-rule-is-bidirectional/m-p/4729487#M1095468</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;do you mean the traffic (port 123) is ntp server to client ? do you mean we don't need to allow client to server traffic ( port 123 ) ?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 05:42:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-rule-is-bidirectional/m-p/4729487#M1095468</guid>
      <dc:creator>MrBeginner</dc:creator>
      <dc:date>2022-11-29T05:42:31Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Rule is bidirectional ?</title>
      <link>https://community.cisco.com/t5/network-security/ntp-rule-is-bidirectional/m-p/4729604#M1095475</link>
      <description>&lt;P&gt;**&lt;BR /&gt;friend there are known port you can use&amp;nbsp;&lt;BR /&gt;permit udp any any eq 123&amp;nbsp;&lt;BR /&gt;OR&amp;nbsp;&lt;BR /&gt;permit udp any any eq ntp&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;and for may lab there are two case&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;***&lt;BR /&gt;&lt;SPAN&gt;NTP Server-inside-FW-outside-NTP client &amp;lt;&amp;lt;- this my lab and since traffic from low to high security level we need ACL&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;or&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;NTP client-inside -FW-outside-NTP Server &amp;lt;&amp;lt;- here you dont need any thing, since traffic from high to low security level&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 10:59:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-rule-is-bidirectional/m-p/4729604#M1095475</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-11-29T10:59:14Z</dc:date>
    </item>
  </channel>
</rss>

