<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NTP Request Reply takes two minutes in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887914#M1102805</link>
    <description>&lt;PRE&gt;nat (dmz,outside) source static any TVuPack2 service 123-UDP 123-UDP unidirectional&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;i tried this but didn't help&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Jul 2023 16:34:16 GMT</pubDate>
    <dc:creator>YaqoobKhalid4217</dc:creator>
    <dc:date>2023-07-19T16:34:16Z</dc:date>
    <item>
      <title>NTP Request Reply takes two minutes</title>
      <link>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887126#M1102735</link>
      <description>&lt;P&gt;Appliance Model : Cisco ASA 5508-X&lt;BR /&gt;Firepower Status : Not used&amp;nbsp;&lt;BR /&gt;ASA Version : 9.16.4&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I am having trouble using NTP to synchronize time on port 123. I have set up a custom NTP server that listens to port 122, and I have verified that the synchronization works fine using the nettime client on a Windows machine. However, when I try to sync time on port 123, I encounter issues.&lt;/P&gt;&lt;P&gt;I checked the debug monitor on ASDM and noticed that the request is being made to the specific NTP server, but the reply takes approximately two minutes to show up on the monitor.&lt;/P&gt;&lt;P&gt;To clarify, I am trying to sync time using NTP, but I am only experiencing issues with port 123. I have set up a custom NTP server that works fine on port 122, but the problem arises when I use port 123. I have checked the debug monitor on the ASDM, and I can see that the request is being sent to the NTP server, but the response takes a long time to show up.&lt;/P&gt;&lt;P&gt;To fix this issue, I have checked the network and firewall settings to ensure that they are not causing any delays or blocking NTP traffic on port 123. I have also verified that the NTP server is correctly configured and responding to requests in a timely manner. Additionally, I have tried using a different NTP server and client to see if the issue persists.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="time between request and reply to show up" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191686i4B12142F12F828F6/image-size/large?v=v2&amp;amp;px=999" role="button" title="IMG_1615.jpg" alt="time between request and reply to show up" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;time between request and reply to show up&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 16:53:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887126#M1102735</guid>
      <dc:creator>YaqoobKhalid4217</dc:creator>
      <dc:date>2023-07-18T16:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Request Reply takes two minutes</title>
      <link>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887194#M1102736</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/985127"&gt;@YaqoobKhalid4217&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; The Tear Down on the log must refers to the UPD session and not related to the NTP. But, sounds to me that the firewall is actually handling the NTP differently when you use the standard port and it is ignoring when doing not standard port.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; I would recommend you to add inspection on the NTP service.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 18:39:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887194#M1102736</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2023-07-18T18:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Request Reply takes two minutes</title>
      <link>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887196#M1102737</link>
      <description>&lt;P&gt;your log is show port 123 not 122&amp;nbsp;&lt;BR /&gt;can I see NTP config ?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 18:41:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887196#M1102737</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-18T18:41:45Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Request Reply takes two minutes</title>
      <link>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887234#M1102739</link>
      <description>&lt;P&gt;yes this is when i try using the ntp on the default port the 123 port and this when the problem occur&amp;nbsp;&amp;nbsp;&lt;BR /&gt;do you need to see&amp;nbsp; the log when i use ntp on the 122 port ? the custom port ?&amp;nbsp;&lt;BR /&gt;do you need the config for the windows ntp client ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 19:33:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887234#M1102739</guid>
      <dc:creator>YaqoobKhalid4217</dc:creator>
      <dc:date>2023-07-18T19:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Request Reply takes two minutes</title>
      <link>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887236#M1102740</link>
      <description>&lt;P&gt;Please asa and ntp server config&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 19:35:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887236#M1102740</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-18T19:35:11Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Request Reply takes two minutes</title>
      <link>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887282#M1102742</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="firewall config for the custom NTP to get the requests" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191726iE015CF2B2BFD5ADA/image-size/large?v=v2&amp;amp;px=999" role="button" title="firewall behind the custom ntp.PNG" alt="firewall config for the custom NTP to get the requests" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;firewall config for the custom NTP to get the requests&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dmz interface on the ASA Config" style="width: 757px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191723iCEFAF3D7BE693077/image-size/large?v=v2&amp;amp;px=999" role="button" title="dmz interface.PNG" alt="dmz interface on the ASA Config" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;dmz interface on the ASA Config&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ntp windows Client with the custom ntp" style="width: 959px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191727i4FD7D5E4E2FC462A/image-size/large?v=v2&amp;amp;px=999" role="button" title="NTP Client.PNG" alt="ntp windows Client with the custom ntp" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;ntp windows Client with the custom ntp&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 20:33:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887282#M1102742</guid>
      <dc:creator>YaqoobKhalid4217</dc:creator>
      <dc:date>2023-07-18T20:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Request Reply takes two minutes</title>
      <link>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887285#M1102743</link>
      <description>&lt;P&gt;But you NATing the port from 122 to 123.&lt;/P&gt;
&lt;P&gt;You must forward same port.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 20:38:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887285#M1102743</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-18T20:38:09Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Request Reply takes two minutes</title>
      <link>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887286#M1102744</link>
      <description>&lt;P&gt;could you explain more ? UPD Session&amp;nbsp;&lt;BR /&gt;where to add the inspection&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 20:38:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887286#M1102744</guid>
      <dc:creator>YaqoobKhalid4217</dc:creator>
      <dc:date>2023-07-18T20:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Request Reply takes two minutes</title>
      <link>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887287#M1102745</link>
      <description>&lt;P&gt;this config on the custom ntp side not on the asa, i did that so i can skip the port 123 issue because on my side where is the asa located&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 20:40:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887287#M1102745</guid>
      <dc:creator>YaqoobKhalid4217</dc:creator>
      <dc:date>2023-07-18T20:40:07Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Request Reply takes two minutes</title>
      <link>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887294#M1102746</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="firewall behind the custom ntp.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191729i178384FF4BF52FB2/image-size/large?v=v2&amp;amp;px=999" role="button" title="firewall behind the custom ntp.PNG" alt="firewall behind the custom ntp.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 20:48:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887294#M1102746</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-18T20:48:49Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Request Reply takes two minutes</title>
      <link>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887298#M1102747</link>
      <description>&lt;P&gt;this is a temp solution to get time sync for the dmz network, so i didn't bothered to config the windows ntp server to allow incoming traffic thought port 123 so i just did the translation on the firewall.&lt;BR /&gt;&lt;BR /&gt;the issue on the ASA the asa handle the ntp traffic with no issues as long as it's not on port 123&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 20:54:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887298#M1102747</guid>
      <dc:creator>YaqoobKhalid4217</dc:creator>
      <dc:date>2023-07-18T20:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Request Reply takes two minutes</title>
      <link>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887305#M1102748</link>
      <description>&lt;P&gt;packet-tracer input DMZ udp (any ip of dmz sunbet except dmz interface IP) 1234 (ntp server) 123&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Share output of above&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 21:08:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887305#M1102748</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-18T21:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Request Reply takes two minutes</title>
      <link>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887309#M1102749</link>
      <description>&lt;P&gt;this topology explain what i used to bypass the issue on the asa&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Randmom.drawio (1).png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191731i24513279F2E6F048/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Randmom.drawio (1).png" alt="Randmom.drawio (1).png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 21:20:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887309#M1102749</guid>
      <dc:creator>YaqoobKhalid4217</dc:creator>
      <dc:date>2023-07-18T21:20:46Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Request Reply takes two minutes</title>
      <link>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887311#M1102750</link>
      <description>&lt;P&gt;but i still have the problem when i ever use ntp on the default port, and as i said the only thing that i noticed is that the request replay takes 2 minutes to show up on the debug monitor&amp;nbsp;&lt;/P&gt;&lt;P&gt;i tried to use multiple public ntp servers but in every time the same issue occurs&amp;nbsp;&lt;BR /&gt;time.google.com&lt;/P&gt;&lt;P&gt;time.windows.com&lt;/P&gt;&lt;P&gt;etc&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 21:24:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887311#M1102750</guid>
      <dc:creator>YaqoobKhalid4217</dc:creator>
      <dc:date>2023-07-18T21:24:24Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Request Reply takes two minutes</title>
      <link>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887316#M1102751</link>
      <description>&lt;P&gt;is this what you need ?&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191732i75CED0F67EEE10BB/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.PNG" alt="1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191733i6347FAB0CEA191A7/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.PNG" alt="2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 21:32:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887316#M1102751</guid>
      <dc:creator>YaqoobKhalid4217</dc:creator>
      <dc:date>2023-07-18T21:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Request Reply takes two minutes</title>
      <link>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887361#M1102753</link>
      <description>&lt;P&gt;any one knows how to fix the issue ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 11:35:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887361#M1102753</guid>
      <dc:creator>YaqoobKhalid4217</dc:creator>
      <dc:date>2023-07-19T11:35:51Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Request Reply takes two minutes</title>
      <link>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887404#M1102754</link>
      <description>&lt;P&gt;tear down happens since its reached the global timeout value for an UDP connection which is 2 minutes&lt;/P&gt;
&lt;P&gt;Check it with show run timout&lt;/P&gt;
&lt;P&gt;I suggested the inspection as a mean to allow the NTP connection but it seems the ntp is not available for inspection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 02:47:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887404#M1102754</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2023-07-19T02:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Request Reply takes two minutes</title>
      <link>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887614#M1102769</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Randmom.drawio (1).png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191823iD9F4BCE7CE1901F0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Randmom.drawio (1).png" alt="Randmom.drawio (1).png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 09:53:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887614#M1102769</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-19T09:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Request Reply takes two minutes</title>
      <link>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887663#M1102773</link>
      <description>&lt;P&gt;below i explained what you asked for .&lt;BR /&gt;to clarify things more the diagram that i draw is only to show the bypass solution (the temp solution) to get thing running while i try to solve the main issue with the port 123 and the weird behavior of ASA with this specific port&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;so any thought why ASA takes 2 minutes to show the reply request ? for the NTP Traffic on port 123 ?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RD.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191825iD36F24EBCD8B016C/image-size/large?v=v2&amp;amp;px=999" role="button" title="RD.png" alt="RD.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 11:59:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887663#M1102773</guid>
      <dc:creator>YaqoobKhalid4217</dc:creator>
      <dc:date>2023-07-19T11:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Request Reply takes two minutes</title>
      <link>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887673#M1102774</link>
      <description>&lt;P&gt;does ASA also use same NTP server ?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 12:08:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-request-reply-takes-two-minutes/m-p/4887673#M1102774</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-19T12:08:28Z</dc:date>
    </item>
  </channel>
</rss>

