Skip to Content.
Sympa Menu

netsec-sig - Re: [Security-WG] I2 - Turning off NTP?

Subject: Internet2 Network Security SIG

List archive

Re: [Security-WG] I2 - Turning off NTP?


Chronological Thread 
  • From: John Kristoff <>
  • To: gcbrowni <>
  • Cc: "" <>
  • Subject: Re: [Security-WG] I2 - Turning off NTP?
  • Date: Tue, 25 Jul 2017 11:07:20 -0500
  • Ironport-phdr: 9a23:M1M/VhXReCSeWdyDpiXseTv5F8DV8LGtZVwlr6E/grcLSJyIuqrYYxCCt8tkgFKBZ4jH8fUM07OQ6PGwHzRYqb+681k6OKRWUBEEjchE1ycBO+WiTXPBEfjxciYhF95DXlI2t1uyMExSBdqsLwaK+i764jEdAAjwOhRoLerpBIHSk9631+ev8JHPfglEnjSwbLdxIRmssQndqtQdjJd/JKo21hbHuGZDdf5MxWNvK1KTnhL86dm18ZV+7SleuO8v+tBZX6nicKs2UbJXDDI9M2Ao/8LrrgXMTRGO5nQHTGoblAdDDhXf4xH7WpfxtTb6tvZ41SKHM8D6Uaw4VDK/5KptVRTmijoINyQh/W/ZisJ+kr9VrhGjqBxx2Y7bb52aOvVlc6PBZNMXX3ZNUtpNWyFDBI63cosBD/AGPeZdt4Tzo1wOrRu4BQKxAe3v0D5IhmTq3a093eQhHxzN0QsiH9ISs3TZt8j6O7kKUe+v0anIyS/PYO1L1jfg8YXFdA0qr/KUXb9obMbcxlUjGxnYgliUt4DpJS2Z2vkOvmSB8uZtW/yjhmg6oA9ruDev3N0jiozRi4IV1F/E8SJ5zZ4vKt24UkF7e8akHIFRtyGdLYt5XtkuTHx2tyYi0LIGpJq7cDIUx5s62h7Tc/2Hc46W7RL/TOudPDh1iG5/dL6igxu+71KsxvPhWsS3ylpGsyRInsfUunAIzRPT68yHSvVn/kem3DaCzwLT6v1HIU0viKXUNYYhzaQtlpoXq0jMADL5mFjugK+Makok4vSo6/jgYrj+vZ+TKZN7ihzkMqQvhsy+Af00MwYBX2WA/eS81abj/VHiQLlUlPE2k6/ZsIzEKsQBoK62HRNV3pg55xmhEjimzYdQoX5SI1lPYhWYiYmhb17FKur/EvG+q1uolz1iw/bBNfvgH9PAImWVw43sZbJs10kJyhYw5dlf7ohMTLAGOvm1VkLpvcHcSBI1Ll+a2eHiXfd61oVWeniOGbOePq2a5V2U5cojLvGFeYtTtTrgfat2r8XyhGM0zAdONZKi2oEaPSi1

On Tue, 25 Jul 2017 13:59:47 +0000
gcbrowni
<>
wrote:

> I wonder if anyone would be interested in engaging in a though
> experiment with me on turning off NTP on the routers?

Might the question be more general, such as "what would the effect of
not having a synchronized clock on a router be?" Or do you care
specifically about NTP?

> 2) You loose the ability to easily correlate messages between routers
> if their clocks don’t match. I suspect this is mostly a non-issue
> since most(?) are sending logs to something like Splunk which can
> stamp the time for correlation purposes?

Won't some log collectors also keep the time stamp from the local
system? So the inconvenience may be more widespread.

If you want to do RPKI, having an accurate notion is going to be
desirable.

You might also want good clocks for NetFlow/IPFIX collectors if you
export flows.

> Anyone have thoughts or observations on this?

It seems unlikely to cause any serious operational issues on most
networks, but I'm not convinced removing it is better than keeping it.
I think the inconvenience is going to add up quickly for most "serious"
operators.

> is NTP still relevant on routers and/or does it justify the risk of
> running it?

Perhaps enumerate the risks as well. Depending on the router for
example, a default, accessible NTP service:

* may unwittingly become a reflector/amplifier
* may enable an information leak
* may present a CPU/packet DoS condition
* may expose an unauthenticated path into the system

John



Archive powered by MHonArc 2.6.19.

Top of Page