Firewalled NTP on Redhat - ntpdate works, but ntpq doesn't

Herta Van den Eynde herta.vandeneynde at gmail.com
Fri May 18 19:57:57 UTC 2007


On 18/05/07, Young, Mike <Mike.Young at atosorigin.com> wrote:
> Hello,
>
> I'm seeing an odd NTP problem on a couple of Redhat servers here.  Basically the NTP client is on a firewalled DMZ, away from the NTP server.  NTP updates via ntpq work fine on the local NTP server subnet, but it isn't working for hosts on the firewalled DMZ.  We've checked ports on the firewall, and 123/UDP is open.  In addition, we see packets incrementing when we use the "iostat" command in ntpdc, and don't see any dropped or ignored packets in iostat either.
>
> Any ideas?
>
> Thanks,
> Mike.

The ntp server uses 123/UDP, the client use ports above 1023.
http://www.unix.org.ua/orelly/networking/firewall/ch08_13.htm suggests
setting up an ntp server on your DMZ.

Kind regards,

Herta




More information about the redhat-list mailing list