<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NTP through a VPN tunnel in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963226#M1106053</link>
    <description>&lt;P&gt;Yep, VPN is up, a windows client behind the ASA can talk to the NTP server without issue.&amp;nbsp; The ASA however doesn't seem to be able to communicate with it.&lt;/P&gt;</description>
    <pubDate>Mon, 20 Nov 2023 19:56:29 GMT</pubDate>
    <dc:creator>irbk</dc:creator>
    <dc:date>2023-11-20T19:56:29Z</dc:date>
    <item>
      <title>NTP through a VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963038#M1106023</link>
      <description>&lt;P&gt;I would like to setup sort of a single source of truth for time on the network.&amp;nbsp; Our WatchGuard box at HQ already has pool.ntp configured on it and our servers are then getting NTP data from the WatchGuard.&amp;nbsp; I'd like to also have the ASA 5525, who is on the other side of a VPN tunnel to the WatchGuard, using the WatchGuard as his NTP source.&amp;nbsp; I've configured the ASA with&lt;BR /&gt;ntp server &amp;lt;ip of WatchGuard&amp;gt; source &amp;lt;vlan with firewall rules allowing NTP through to the WatchGuard&amp;gt;&lt;BR /&gt;The vlan above has other servers that are able to get NTP from the WatchGuard without issue.&amp;nbsp; I'm guessing that the NTP packets from the ASA aren't really being sourced from the right interface or something?&amp;nbsp; Even though I've specified a source.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 15:47:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963038#M1106023</guid>
      <dc:creator>irbk</dc:creator>
      <dc:date>2023-11-20T15:47:53Z</dc:date>
    </item>
    <item>
      <title>Re: NTP through a VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963052#M1106024</link>
      <description>&lt;P&gt;So the issue you see on ASA only ?&lt;/P&gt;
&lt;P&gt;is the Same ASA doing VPN ?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 15:56:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963052#M1106024</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-11-20T15:56:36Z</dc:date>
    </item>
    <item>
      <title>Re: NTP through a VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963057#M1106025</link>
      <description>&lt;P&gt;Correct, the ASA is doing the VPN tunnel to the WatchGuard.&amp;nbsp; I'm wondering if the ASA can't send traffic through the tunnel when the source of the traffic is itself.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 15:58:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963057#M1106025</guid>
      <dc:creator>irbk</dc:creator>
      <dc:date>2023-11-20T15:58:15Z</dc:date>
    </item>
    <item>
      <title>Re: NTP through a VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963062#M1106026</link>
      <description>&lt;P&gt;Yes, the command "ntp server &amp;lt;ip&amp;gt; source &amp;lt;int&amp;gt;" takes IP from the specified interface, but the request is still routed via the routing table and doesn't make it into VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 16:03:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963062#M1106026</guid>
      <dc:creator>tvotna</dc:creator>
      <dc:date>2023-11-20T16:03:16Z</dc:date>
    </item>
    <item>
      <title>Re: NTP through a VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963067#M1106027</link>
      <description>&lt;P&gt;Shoot, any way to fix that?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 16:07:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963067#M1106027</guid>
      <dc:creator>irbk</dc:creator>
      <dc:date>2023-11-20T16:07:52Z</dc:date>
    </item>
    <item>
      <title>Re: NTP through a VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963068#M1106028</link>
      <description>&lt;P&gt;Use inside as source interface to connect to NTP&lt;/P&gt;
&lt;P&gt;Use access management for inside&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And then check again&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 16:10:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963068#M1106028</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-11-20T16:10:59Z</dc:date>
    </item>
    <item>
      <title>Re: NTP through a VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963069#M1106029</link>
      <description>&lt;P&gt;is the NTP destination IP part of Intersting traffic of Tunnel ?&lt;/P&gt;
&lt;P&gt;check NTP can use over IPSEC&amp;nbsp; (personally i dont like to use NTP - prefer to have local)&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113421-asa83-ntp-config-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113421-asa83-ntp-config-00.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 16:11:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963069#M1106029</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-11-20T16:11:29Z</dc:date>
    </item>
    <item>
      <title>Re: NTP through a VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963074#M1106030</link>
      <description>&lt;P&gt;I don't have "inside" as an actual configured interface however the interface that I used is an "inside" interface.&amp;nbsp; You think it might be a Management access rule issue?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 16:13:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963074#M1106030</guid>
      <dc:creator>irbk</dc:creator>
      <dc:date>2023-11-20T16:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: NTP through a VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963077#M1106031</link>
      <description>&lt;P&gt;Yes, the destination IP is part of interesting traffic to the tunnel.&amp;nbsp;&lt;BR /&gt;I've seen that article before I posted this question but didn't find it helpful, but thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 16:16:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963077#M1106031</guid>
      <dc:creator>irbk</dc:creator>
      <dc:date>2023-11-20T16:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: NTP through a VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963078#M1106032</link>
      <description>&lt;P&gt;You use vpn s2s what is interface connect to LAN allow in vpn acl?&lt;/P&gt;
&lt;P&gt;Use it as source for ntp.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 16:16:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963078#M1106032</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-11-20T16:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: NTP through a VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963081#M1106033</link>
      <description>&lt;P&gt;Yes, that's what I'm doing.&amp;nbsp; Interface "corp" is one of many vlans which are "internal" and the source that I'm putting for the NTP command.&amp;nbsp; Same interface has an ACL allowing the corp/24 network to the WatchGuard on 123.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 16:20:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963081#M1106033</guid>
      <dc:creator>irbk</dc:creator>
      <dc:date>2023-11-20T16:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: NTP through a VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963097#M1106035</link>
      <description>&lt;P&gt;Add&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Management-access &lt;STRONG&gt;corp&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Then check ntp sync&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 16:39:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963097#M1106035</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-11-20T16:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: NTP through a VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963112#M1106037</link>
      <description>&lt;P&gt;Try using interface internal in your case "corp"&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 16:50:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963112#M1106037</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-11-20T16:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: NTP through a VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963221#M1106050</link>
      <description>&lt;P&gt;Sorry it took me so long to reply but I wanted to lab this up before giving it a try.&amp;nbsp; Adding the management-access cmd didn't change anything.&amp;nbsp; AAMOF in a packet capture I don't even see the ASA trying to send packets through the tunnel.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 19:52:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963221#M1106050</guid>
      <dc:creator>irbk</dc:creator>
      <dc:date>2023-11-20T19:52:24Z</dc:date>
    </item>
    <item>
      <title>Re: NTP through a VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963222#M1106051</link>
      <description>&lt;P&gt;Yeah the&lt;BR /&gt;&lt;SPAN&gt;ntp server &amp;lt;ip of WatchGuard&amp;gt; source &amp;lt;vlan with firewall rules allowing NTP through to the WatchGuard&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;source as listed above is "corp"&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 19:54:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963222#M1106051</guid>
      <dc:creator>irbk</dc:creator>
      <dc:date>2023-11-20T19:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: NTP through a VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963224#M1106052</link>
      <description>&lt;P&gt;Take your time&lt;/P&gt;
&lt;P&gt;Check vpn ot must be up.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 19:55:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963224#M1106052</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-11-20T19:55:25Z</dc:date>
    </item>
    <item>
      <title>Re: NTP through a VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963226#M1106053</link>
      <description>&lt;P&gt;Yep, VPN is up, a windows client behind the ASA can talk to the NTP server without issue.&amp;nbsp; The ASA however doesn't seem to be able to communicate with it.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 19:56:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963226#M1106053</guid>
      <dc:creator>irbk</dc:creator>
      <dc:date>2023-11-20T19:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: NTP through a VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963235#M1106055</link>
      <description>&lt;P&gt;Management access is solution here.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 20:05:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963235#M1106055</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-11-20T20:05:12Z</dc:date>
    </item>
    <item>
      <title>Re: NTP through a VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963238#M1106056</link>
      <description>&lt;P&gt;I've added the management access for inside as you suggested but it doesn't change anything.&amp;nbsp; Let me rephrase that, I could ping to the remote server from the ASA, which I couldn't do before the management access inside command, so it's not that the command had no effect.&amp;nbsp; However still no NTP.&amp;nbsp; Still unsynchronized and insane.&amp;nbsp; Plus I wouldn't want to enable that management access in production.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 20:26:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-through-a-vpn-tunnel/m-p/4963238#M1106056</guid>
      <dc:creator>irbk</dc:creator>
      <dc:date>2023-11-20T20:26:50Z</dc:date>
    </item>
  </channel>
</rss>

