<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NTP - Configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ntp-configuration/m-p/2337435#M344413</link>
    <description>&lt;P&gt;Hi Gurus of Cisco&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I want to synchronize my devices that are on the outside interface (please see the image bellow)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/3/6/6/151663-NTP%20Scenario.jpg" alt="NTP Scenario.jpg" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;My Firewall has the following configuration:&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 181.66.39.100 255.255.255.128&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.1.8.101 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My NTP server is 10.1.11.12 and is on the VLAN 11 (10.1.11.0/24) of my core Switch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From my core network I can reach the two devices that are outside the interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;CORE-SWITCH#ping 181.66.39.98 source vlan 11 repeat 20&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Type escape sequence to abort.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Sending 20, 100-byte ICMP Echos to 181.66.39.98, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;Packet sent with a source address of 10.1.11.3&lt;/P&gt;&lt;P&gt;!!!!!!!!!!!!!!!!!!!!&lt;/P&gt;&lt;P&gt;Success rate is 100 percent (20/20), round-trip min/avg/max = 1/2/16 ms&lt;/P&gt;&lt;P&gt;CORE-SWITCH#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If run the ASDM tool "Packet tracer", select Interface "Inside", Packet Type "UDP", Source Address &lt;SPAN style="font-size: 10pt;"&gt;10.1.11.12, Source Port NTP ---&amp;gt; Destination Address &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;181.66.39.98, Destination Port NTP ---&amp;gt; I can Reach, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; packet-tracer input inside udp 10.1.11.12 ntp &lt;SPAN style="font-size: 10pt;"&gt;181.66.39.98 &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;ntp&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;The Result is:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: inside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: outside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But in &lt;SPAN style="font-size: 10pt;"&gt;the other direction&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input outside udp &lt;SPAN style="font-size: 10pt;"&gt;181.66.39.98 &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;ntp 10.1.11.12 ntp&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 6&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: rpf-check&lt;/P&gt;&lt;P&gt;Result: DROP&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;nat (inside) 2 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip inside any outside any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 2 (&lt;SPAN style="font-size: 10pt;"&gt;181.66.39.&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;102)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 2129309899, untranslate_hits = 249021388&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: outside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: inside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: drop&lt;/P&gt;&lt;P&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In base of line above detail?, what lines I must be add to my firewall configuration &lt;SPAN style="font-size: 10pt;"&gt;to synchronize &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;my devices that are on the outside interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Any comments or sugestion is welcome&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 02:27:42 GMT</pubDate>
    <dc:creator>a.guillen</dc:creator>
    <dc:date>2019-03-12T02:27:42Z</dc:date>
    <item>
      <title>NTP - Configuration</title>
      <link>https://community.cisco.com/t5/network-security/ntp-configuration/m-p/2337435#M344413</link>
      <description>&lt;P&gt;Hi Gurus of Cisco&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I want to synchronize my devices that are on the outside interface (please see the image bellow)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/3/6/6/151663-NTP%20Scenario.jpg" alt="NTP Scenario.jpg" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;My Firewall has the following configuration:&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 181.66.39.100 255.255.255.128&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.1.8.101 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My NTP server is 10.1.11.12 and is on the VLAN 11 (10.1.11.0/24) of my core Switch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From my core network I can reach the two devices that are outside the interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;CORE-SWITCH#ping 181.66.39.98 source vlan 11 repeat 20&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Type escape sequence to abort.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Sending 20, 100-byte ICMP Echos to 181.66.39.98, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;Packet sent with a source address of 10.1.11.3&lt;/P&gt;&lt;P&gt;!!!!!!!!!!!!!!!!!!!!&lt;/P&gt;&lt;P&gt;Success rate is 100 percent (20/20), round-trip min/avg/max = 1/2/16 ms&lt;/P&gt;&lt;P&gt;CORE-SWITCH#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If run the ASDM tool "Packet tracer", select Interface "Inside", Packet Type "UDP", Source Address &lt;SPAN style="font-size: 10pt;"&gt;10.1.11.12, Source Port NTP ---&amp;gt; Destination Address &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;181.66.39.98, Destination Port NTP ---&amp;gt; I can Reach, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; packet-tracer input inside udp 10.1.11.12 ntp &lt;SPAN style="font-size: 10pt;"&gt;181.66.39.98 &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;ntp&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;The Result is:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: inside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: outside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But in &lt;SPAN style="font-size: 10pt;"&gt;the other direction&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input outside udp &lt;SPAN style="font-size: 10pt;"&gt;181.66.39.98 &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;ntp 10.1.11.12 ntp&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 6&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: rpf-check&lt;/P&gt;&lt;P&gt;Result: DROP&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;nat (inside) 2 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip inside any outside any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 2 (&lt;SPAN style="font-size: 10pt;"&gt;181.66.39.&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;102)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 2129309899, untranslate_hits = 249021388&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: outside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: inside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: drop&lt;/P&gt;&lt;P&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In base of line above detail?, what lines I must be add to my firewall configuration &lt;SPAN style="font-size: 10pt;"&gt;to synchronize &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;my devices that are on the outside interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Any comments or sugestion is welcome&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:27:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-configuration/m-p/2337435#M344413</guid>
      <dc:creator>a.guillen</dc:creator>
      <dc:date>2019-03-12T02:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: NTP - Configuration</title>
      <link>https://community.cisco.com/t5/network-security/ntp-configuration/m-p/2337436#M344414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;NTP is typically used in a client/server-way where the two routers would be the client and the core-switch is the server. With that you have incoming connections from outside to inside. For that you not only need a permit-entry in your outside-ACL, but also a matching static-NAT-statement or a nat-excemption for that traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The config could look like the folowing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;object-group network NTP-SERVER&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; network-object host 181.66.39.98&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; network-object host 181.66.39.99&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;access-list NAT-EXEMPT permit ip host 10.1.11.12 object-group NTP-SERVER&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;nat (inside) 0 access-list NAT-EXEMPT&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Probably there is aready a NAT-exemption on your inide interface so that you have to add it to your actual config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni" rel="nofollow"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Aug 2013 07:06:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-configuration/m-p/2337436#M344414</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-08-20T07:06:57Z</dc:date>
    </item>
  </channel>
</rss>

