FB_security 板


In message <[email protected]>, Charles Swiger <[email protected]> wrote: >If you don't want to provide NTP service to the outside world, leave your existing >deny rule in place but add permit rules to allow UDP traffic to and from the >NTP servers which you want to sync time from. I just now tried doing that, but what I tried doesn't seem to be working at all as expected. My effort has however releaved more of my ignorance about ntpd and ntpdc. Starting from these lines in my /etc/ntp.conf file: server 0.freebsd.pool.ntp.org iburst server 1.freebsd.pool.ntp.org iburst server 2.freebsd.pool.ntp.org iburst I resolved each of those three host names to _all_ of its associated IPv4 addresses. This yielded me the following list: 50.116.38.157 69.50.219.51 69.55.54.17 69.167.160.102 108.61.73.244 129.250.35.251 149.20.68.17 169.229.70.183 192.241.167.38 199.7.177.206 209.114.111.1 209.118.204.201 So I added the following new ipfw rules, just above the deny rule that I currently have protecting my UDP port 123: add pass udp from 50.116.38.157 123 to any in add pass udp from 69.50.219.51 123 to any in add pass udp from 69.55.54.17 123 to any in add pass udp from 69.167.160.102 123 to any in add pass udp from 108.61.73.244 123 to any in add pass udp from 129.250.35.251 123 to any in add pass udp from 149.20.68.17 123 to any in add pass udp from 169.229.70.183 123 to any in add pass udp from 192.241.167.38 123 to any in add pass udp from 199.7.177.206 123 to any in add pass udp from 209.114.111.1 123 to any in add pass udp from 209.118.204.201 123 to any in I then cd'd into /etc/rc.conf and executed the following (as root): ../ntpd stop ../ntpd start Then, after a short while, I ran ntpdc again and executed the "peers" query again. Now I get this: remote local st poll reach delay offset disp ======================================================================= =cheezum.mattnor 69.62.255.118 16 64 0 0.00000 0.000000 3.99217 *server2.shellva 69.62.255.118 2 64 377 0.09827 0.021492 0.05600 =li506-17.member 69.62.255.118 16 64 0 0.00000 0.000000 3.99217 Obviously, this is better than before... I am now syncing with at least one server (specifically 69.55.54.17 server2.shellvatore.us), *however* I have checked the reverse DNS names associated with all 12 of the above listed IPv4 addresses and none of those reverse DNS names begin with either "cheezum.mattnor..." or "li506-17.member...". So um, color me preplexed! It appears that ntpdc is telling me that my local ntpd daemon is attempting to query a couple of remote time servers that I never asked it to consult! What's up with that? Furthermore, and consistant with what ntpdc is telling me, only one of my new firewall rules is even succeeding at letting any useful NTP packets through, specifically ones being sent to me from server2.shellvatore.us: 01605 0 0 allow udp from 50.116.38.157 123 to any in 01610 0 0 allow udp from 69.50.219.51 123 to any in 01615 20 1520 allow udp from 69.55.54.17 123 to any in 01620 0 0 allow udp from 69.167.160.102 123 to any in 01625 0 0 allow udp from 108.61.73.244 123 to any in 01630 0 0 allow udp from 129.250.35.251 123 to any in 01635 0 0 allow udp from 149.20.68.17 123 to any in 01640 0 0 allow udp from 169.229.70.183 123 to any in 01645 0 0 allow udp from 192.241.167.38 123 to any in 01650 0 0 allow udp from 199.7.177.206 123 to any in 01655 0 0 allow udp from 209.114.111.1 123 to any in 01660 0 0 allow udp from 209.118.204.201 123 to any in So, um, what the bleep goes on here? Why is my ntpd only querying one of the 12 possible IPv4 addresses it should be querying? And why is it sending queries to two servers that, as far as I can tell, I never told it to send queries to, specifically: 67.18.187.111 cheezum.mattnordhoff.net 66.175.209.17 li506-17.members.linode.com Is there some secret extra .conf file for ntpd that I don't know about? For reference, my own complete & current /etc/ntp.conf file is attached below: cut here ============================================================================= # # $FreeBSD: release/9.1.0/etc/ntp.conf 239608 2012-08-23 04:57:56Z delphij $ # # Default NTP servers for the FreeBSD operating system. # # Don't forget to enable ntpd in /etc/rc.conf with: # ntpd_enable="YES" # # The driftfile is by default /var/db/ntpd.drift, check # /etc/defaults/rc.conf on how to change the location. # # # The following three servers will give you a random set of three # NTP servers geographically close to you. # See http://www.pool.ntp.org/ for details. Note, the pool encourages # users with a static IP and good upstream NTP servers to add a server # to the pool. See http://www.pool.ntp.org/join.html if you are interested. # # The option `iburst' is used for faster initial synchronisation. # server 0.freebsd.pool.ntp.org iburst server 1.freebsd.pool.ntp.org iburst server 2.freebsd.pool.ntp.org iburst #server 3.freebsd.pool.ntp.org iburst # # If you want to pick yourself which country's public NTP server # you want sync against, comment out the above servers, uncomment # the next ones and replace CC with the country's abbreviation. # Make sure that the hostnames resolve to a proper IP address! # # server 0.CC.pool.ntp.org iburst # server 1.CC.pool.ntp.org iburst # server 2.CC.pool.ntp.org iburst # # Security: Only accept NTP traffic from the following hosts. # The following configuration example only accepts traffic from the # above defined servers. # # Please note that this example doesn't work for the servers in # the pool.ntp.org domain since they return multiple A records. # (This is the reason that by default they are commented out) # #restrict default ignore #restrict 0.pool.ntp.org nomodify nopeer noquery notrap #restrict 1.pool.ntp.org nomodify nopeer noquery notrap #restrict 2.pool.ntp.org nomodify nopeer noquery notrap #restrict 127.0.0.1 #restrict -6 ::1 #restrict 127.127.1.0 # # If a server loses sync with all upstream servers, NTP clients # no longer follow that server. The local clock can be configured # to provide a time source when this happens, but it should usually # be configured on just one server on a network. For more details see # http://support.ntp.org/bin/view/Support/UndisciplinedLocalClock # The use of Orphan Mode may be preferable. # #server 127.127.1.0 #fudge 127.127.1.0 stratum 10 _______________________________________________ [email protected] mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "[email protected]"







like.gif 您可能會有興趣的文章
icon.png[問題/行為] 貓晚上進房間會不會有憋尿問題
icon.pngRe: [閒聊] 選了錯誤的女孩成為魔法少女 XDDDDDDDDDD
icon.png[正妹] 瑞典 一張
icon.png[心得] EMS高領長版毛衣.墨小樓MC1002
icon.png[分享] 丹龍隔熱紙GE55+33+22
icon.png[問題] 清洗洗衣機
icon.png[尋物] 窗台下的空間
icon.png[閒聊] 双極の女神1 木魔爵
icon.png[售車] 新竹 1997 march 1297cc 白色 四門
icon.png[討論] 能從照片感受到攝影者心情嗎
icon.png[狂賀] 賀賀賀賀 賀!島村卯月!總選舉NO.1
icon.png[難過] 羨慕白皮膚的女生
icon.png閱讀文章
icon.png[黑特]
icon.png[問題] SBK S1安裝於安全帽位置
icon.png[分享] 舊woo100絕版開箱!!
icon.pngRe: [無言] 關於小包衛生紙
icon.png[開箱] E5-2683V3 RX480Strix 快睿C1 簡單測試
icon.png[心得] 蒼の海賊龍 地獄 執行者16PT
icon.png[售車] 1999年Virage iO 1.8EXi
icon.png[心得] 挑戰33 LV10 獅子座pt solo
icon.png[閒聊] 手把手教你不被桶之新手主購教學
icon.png[分享] Civic Type R 量產版官方照無預警流出
icon.png[售車] Golf 4 2.0 銀色 自排
icon.png[出售] Graco提籃汽座(有底座)2000元誠可議
icon.png[問題] 請問補牙材質掉了還能再補嗎?(台中半年內
icon.png[問題] 44th 單曲 生寫竟然都給重複的啊啊!
icon.png[心得] 華南紅卡/icash 核卡
icon.png[問題] 拔牙矯正這樣正常嗎
icon.png[贈送] 老莫高業 初業 102年版
icon.png[情報] 三大行動支付 本季掀戰火
icon.png[寶寶] 博客來Amos水蠟筆5/1特價五折
icon.pngRe: [心得] 新鮮人一些面試分享
icon.png[心得] 蒼の海賊龍 地獄 麒麟25PT
icon.pngRe: [閒聊] (君の名は。雷慎入) 君名二創漫畫翻譯
icon.pngRe: [閒聊] OGN中場影片:失蹤人口局 (英文字幕)
icon.png[問題] 台灣大哥大4G訊號差
icon.png[出售] [全國]全新千尋侘草LED燈, 水草
伺服器連線錯誤,造成您的不便還請多多包涵!
「贊助商連結」






like.gif 您可能會有興趣的文章
icon.png[問題/行為] 貓晚上進房間會不會有憋尿問題
icon.pngRe: [閒聊] 選了錯誤的女孩成為魔法少女 XDDDDDDDDDD
icon.png[正妹] 瑞典 一張
icon.png[心得] EMS高領長版毛衣.墨小樓MC1002
icon.png[分享] 丹龍隔熱紙GE55+33+22
icon.png[問題] 清洗洗衣機
icon.png[尋物] 窗台下的空間
icon.png[閒聊] 双極の女神1 木魔爵
icon.png[售車] 新竹 1997 march 1297cc 白色 四門
icon.png[討論] 能從照片感受到攝影者心情嗎
icon.png[狂賀] 賀賀賀賀 賀!島村卯月!總選舉NO.1
icon.png[難過] 羨慕白皮膚的女生
icon.png閱讀文章
icon.png[黑特]
icon.png[問題] SBK S1安裝於安全帽位置
icon.png[分享] 舊woo100絕版開箱!!
icon.pngRe: [無言] 關於小包衛生紙
icon.png[開箱] E5-2683V3 RX480Strix 快睿C1 簡單測試
icon.png[心得] 蒼の海賊龍 地獄 執行者16PT
icon.png[售車] 1999年Virage iO 1.8EXi
icon.png[心得] 挑戰33 LV10 獅子座pt solo
icon.png[閒聊] 手把手教你不被桶之新手主購教學
icon.png[分享] Civic Type R 量產版官方照無預警流出
icon.png[售車] Golf 4 2.0 銀色 自排
icon.png[出售] Graco提籃汽座(有底座)2000元誠可議
icon.png[問題] 請問補牙材質掉了還能再補嗎?(台中半年內
icon.png[問題] 44th 單曲 生寫竟然都給重複的啊啊!
icon.png[心得] 華南紅卡/icash 核卡
icon.png[問題] 拔牙矯正這樣正常嗎
icon.png[贈送] 老莫高業 初業 102年版
icon.png[情報] 三大行動支付 本季掀戰火
icon.png[寶寶] 博客來Amos水蠟筆5/1特價五折
icon.pngRe: [心得] 新鮮人一些面試分享
icon.png[心得] 蒼の海賊龍 地獄 麒麟25PT
icon.pngRe: [閒聊] (君の名は。雷慎入) 君名二創漫畫翻譯
icon.pngRe: [閒聊] OGN中場影片:失蹤人口局 (英文字幕)
icon.png[問題] 台灣大哥大4G訊號差
icon.png[出售] [全國]全新千尋侘草LED燈, 水草

請輸入看板名稱,例如:WOW站內搜尋

TOP