12-16-2016 10:14 AM - edited 03-08-2019 08:36 AM
Dear Community,
Does pointing a cisco router to a public ntp server as a time-source pose any security risk?
Thanks.
Regards,
Isaac.
Solved! Go to Solution.
12-16-2016 12:46 PM
Isaac,
You need some sort of external time server to get the correct timing. One option would be to point your routers and other equipment to your internal servers (domain controllers) to get their timing and than the domain controllers get it from pool.ntp.org. The other option is to point your devices directly to an external resource. pool.ntp.org has many servers across the globe that serve many organizations. As long as you are only allowing NTP and nothing else, I don't think it is a security risk.
HTH
12-16-2016 10:55 AM
Should not be an issue as long as you only allow the NTP pool servers.
HTH
12-16-2016 11:31 AM
Reza,
Thanks for your prompt response.To be more specific and to clarify I intend to use pool.ntp.org from support.ntp.org time servers.Please offer a brief explanation as to why the router would be able to poll this public server but not pose a security risk from the outside.
Regards,
Isaac.
12-16-2016 12:46 PM
Isaac,
You need some sort of external time server to get the correct timing. One option would be to point your routers and other equipment to your internal servers (domain controllers) to get their timing and than the domain controllers get it from pool.ntp.org. The other option is to point your devices directly to an external resource. pool.ntp.org has many servers across the globe that serve many organizations. As long as you are only allowing NTP and nothing else, I don't think it is a security risk.
HTH
12-16-2016 09:15 PM
Reza,
I will proceed with your recommendations.Thanks for the explanation.Keep it up!
Regards,
Isaac.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide