netsec-sig - Re: [Security-WG] I2 - Strange xntpd behavior
Subject: Internet2 Network Security SIG
List archive
- From: gcbrowni <>
- To:
- Subject: Re: [Security-WG] I2 - Strange xntpd behavior
- Date: Mon, 25 Sep 2017 09:49:29 -0400
- Ironport-phdr: 9a23:FkbaFhb9dNc69ehQ6rOJn/7/LSx+4OfEezUN459isYplN5qZr864bnLW6fgltlLVR4KTs6sC0LuG9fi4EUU7or+5+EgYd5JNUxJXwe43pCcHRPC/NEvgMfTxZDY7FskRHHVs/nW8LFQHUJ2mPw6arXK99yMdFQviPgRpOOv1BpTSj8Oq3Oyu5pHfeQtFiT6+bL9oMBm6sRjau9ULj4dlNqs/0AbCrGFSe+RRy2NoJFaTkAj568yt4pNt8Dletuw4+cJYXqr0Y6o3TbpDDDQ7KG81/9HktQPCTQSU+HQRVHgdnwdSDAjE6BH6WYrxsjf/u+Fg1iSWIdH6QLYpUjmk8qxlSgLniD0fOjA57G7YhdF+gqxVoBy/pRNxwJXZYI6JOPp7ZK7RYc8WSGhHU81MVyJBGIS8b44XAuoOIelXtJP9p1wArBu4BAmnGeTiyjBUiXDtx6061OogEQfH3AE7ENIOtHPUo87vO6cWV+C1y7XHwS/Cb/NLwzvy9pXHcg04rPyKQLl+f83RyUw1GAPEiFWdsY3lPzWJ1usTqWib6fRvVf6xh2I9tQ5+vyWvyt8qionPgIIVzErI9SNnz4YpI9CzVU11Yca8HZdOqy2WK5Z6T8Y/T2xrpik3ybgLuZC1fCQW1JgqwgDTZvKCfoWN4h/vSeCcKipiin1/YrKwnROy/FCgyuLiUsm0105Hri9fndnNsnABzQDc6tSbRfdn8UehwzCP1wfP5e1eIEA0iLDXJIA8zb4tjpYTsELDETHqmEjukqOaalko9vWt5uj6YbjpuJyROop6igHwLqgihsmyDfo2PwULWmWW+fmw2KXm/ULjQbVKivM2krPesJDfPckbqbK2DBRP0oYk5Re/CTam3c8XnXkDK1JKYwiIj4zvO1HJPP/0F/a/g0m2nDh12v/GI6XtAo/RIXjbjLfhYbF95lZHyAUt0d9f+ohUCrAdIPPzQ0PwutPYAwQ9Mwy12ObnFM592p0EVWKOBK+ZLL3dsUWO5u0xP+mAepUZtyjgJPg4tLbSiioilFQAZ6i1zN4IZ1i5GOhrOUOUfSCqj9scQkkQuQ9rQ+fgklqdVz8bM3m5Vbg7+Tc6II2iCo3KQoaqi/qAwWG2EoAANTMOMUyFDXq9L9bMYPwLci/HesI=
Yeah, I checked the multiple loopback thing. No dice. And the FXP’s are not up. Juniper let us in on some new NTP commands. We tried it on one of the nodes and it doesn’t log the message anymore ... implying that this WAS in response to a received request from a packet. I’m willing to say now that it’s not being self-generated, eliminating option #6. We’re still working on additional data gathering techniques. We’re apprehensive about "fixing" it without understanding what was causing it. NTP It looks like this works in the 15.1 code train, and, while not perfect, gets us a long way to shutting off the server capabilities of the NTP system on the Juniper routers: set system ntp restrict noquery set system ntp restrict noserve On Sep 22, 2017, at 11:58 AM, Richard Angeletti <> wrote: |
Attachment:
smime.p7s
Description: S/MIME cryptographic signature
- [Security-WG] I2 - Strange xntpd behavior, gcbrowni, 09/22/2017
- Re: [Security-WG] I2 - Strange xntpd behavior, Andrew Gallo, 09/22/2017
- Re: [Security-WG] I2 - Strange xntpd behavior, gcbrowni, 09/22/2017
- Message not available
- Re: [Security-WG] I2 - Strange xntpd behavior, John Kristoff, 09/22/2017
- Re: [Security-WG] I2 - Strange xntpd behavior, Richard Angeletti, 09/22/2017
- Re: [Security-WG] I2 - Strange xntpd behavior, gcbrowni, 09/25/2017
- Re: [Security-WG] I2 - Strange xntpd behavior, Andrew Gallo, 09/22/2017
- <Possible follow-up(s)>
- Re: [Security-WG] I2 - Strange xntpd behavior, John Kristoff, 09/22/2017
Archive powered by MHonArc 2.6.19.