Skip to Content.
Sympa Menu

netsec-sig - [Security-WG] I2 - Turning off NTP?

Subject: Internet2 Network Security SIG

List archive

[Security-WG] I2 - Turning off NTP?


Chronological Thread 
  • From: gcbrowni <>
  • To:
  • Subject: [Security-WG] I2 - Turning off NTP?
  • Date: Tue, 25 Jul 2017 09:59:47 -0400
  • Ironport-phdr: 9a23:zDmkhBaPyctJA//Gsdic24H/LSx+4OfEezUN459isYplN5qZoMm8bnLW6fgltlLVR4KTs6sC0LuG9fi4EUU7or+5+EgYd5JNUxJXwe43pCcHRPC/NEvgMfTxZDY7FskRHHVs/nW8LFQHUJ2mPw6arXK99yMdFQviPgRpOOv1BpTSj8Oq3Oyu5pHfeQtFiT6+bL9oMBm6sRjau9ULj4dlNqs/0AbCrGFSe+RRy2NoJFaTkAj568yt4pNt8Dletuw4+cJYXqr0Y6o3TbpDDDQ7KG81/9HktQPCTQSU+HQRVHgdnwdSDAjE6BH6WYrxsjf/u+Fg1iSWIdH6QLYpUjmk8qxlSgLniD0fOjA57G7YhdF+gqFVrhy/vBF/zJLYYISPOfZiYq/Qf9UXTndBUMZLUCxBB5uxb4QTAOUaJ+ZYqIf8p10PrRCjAgSsC//gxSRShn/x06w61eUhHBrJ3AwkGNIBq27brNHzNKcVTe+51qjIzSjZY/xIxDj99ZHFfxY8qv+PRbJ9adTdxVUzGw/Yi1ictI/oMC2W2+kIvWib4fZsWf6qhmI5pQx8pz2iy8cxhoTPm4kb0ErL9T9jz4YwPdC4SFB0YdqjEJZIsiGVLYp2Qsc4T250pCY11qcKuZGhfCgMz5Qo2wTTa/2ac4SS/B3sSfuRLS95hHJjZr2/mw6//Va8xuHgS8W51UtGoylbndTPs30N2RLT5tSbRvZ44Eus1zOC2gXT5+1ZOUw0kLDUK58lwr4+jJoTtkHDEzf5mErql6CWbEIk++au6+TmebjmqZucN4hvhQ7kNqQunMu/DvgiPggPQmiX4/qz26D+/UHhWrVFkuU2krXFsJDdPckbvbC2DBNI0oY56ha/Ezen3M0WnHkIN19FfBOHj5P1O1HVPvz0F/a/g1KwkDh13fDGOKPuAonTInTZjrjuYKt9uAZgz18owNtC/ZNIG/QeL9ryXFP8rtrVEkV/PgCpkMj9D9Ao2YgUQ2WQBK7RZKzZu0WP+eQuC+aIY4UcvDD6IL4k+rjjgWJvygxVRrWgwZZCMCPwJf9hOUjMOXc=

I wonder if anyone would be interested in engaging in a though experiment
with me on turning off NTP on the routers?

The Junipers, I believe, act as both clients and servers for NTP, with no
options for disabling the server capability other than through filtering. I
wonder, then, what the impact of simply disabling ALL NTP on the router would
be?

1) I think you loose some convenance capabilities as you look through log
files on the router, assuming non-trivial clock drift. You have to show
system time to recall that the router thinks its yesterday, before looking at
the log files on the box proper.

2) You loose the ability to easily correlate messages between routers if
their clocks don’t match. I suspect this is mostly a non-issue since most(?)
are sending logs to something like Splunk which can stamp the time for
correlation purposes? IE: the you stamp on Splunk and only look at time
correlated/aggravated messages on that box then why do you need accurate
clock on the routers proper?

3) I suppose there’s a corner case of a corner case where you loose your
Splunk logs, and thus correlation and are forced to correlate ‘by hand’ from
the router logs proper.

Anyone have thoughts or observations on this? I’m not proposing it be done,
just asking some thought questions … is NTP still relevant on routers and/or
does it justify the risk of running it?

-G




Attachment: smime.p7s
Description: S/MIME cryptographic signature




Archive powered by MHonArc 2.6.19.

Top of Page