Hi,

On Sat, Mar 22, 2014 at 02:35:55PM +0000, Drew Weaver wrote:
> I just applied an ACL to the ntp command and that fixed it, 

Yeah, that's what you need to do.

> but you have to wonder why configuring an IOS device to synchronize with an 
> external source would explicitly mean that you also want that IOS device to 
> also be a clock source itself.
> 
> That seems like a mistake given the current climate we are in (amp attacks)...

Well, the underlying train of thought in the NTP community seems to be
"there are no servers or clients, just machines running NTP" (which 
reflects in "packets have source+destination = UDP/123" and in other 
aspects, leading to stuff like the ping-pong attacks where you bounce
one NTP error packet endlessly between two servers...).

Back in the day, that wasn't harmful, and I found it convenient at 
times ("just sync the switch to the nearest router"), but nowadays, 
it's backfiring.  So it would be good to have a switch to differenciate 
between "(s)ntp client" and "full ntp functionality".

Until then, spread the word of Cymru's Secure NTP template...

http://www.team-cymru.org/ReadingRoom/Templates/secure-ntp-template.html

... has all you need for IOS, JunOS, Unix, ..

gert
-- 
USENET is *not* the non-clickable part of WWW!
                                                           //www.muc.de/~gert/
Gert Doering - Munich, Germany                             [email protected]
fax: +49-89-35655025                        [email protected]

Attachment: pgp0AtNyJ1Enc.pgp
Description: PGP signature

_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to