BUG? Sophos Switch DoS Prevention blocks time synchronization of devices.

I'm editing my post here.

I have a Sophos CS110-24 switch

I noticed that no devices on my LAN could contact any NTP server to synchronize their time. I found out that it was the DoS prevention setting.

When enabled, no devices can synchronize to any NTP.

Immediately after disable the DoS protection, all devices can receive time updates. I have left DoS prevention off for now.

I have the latest firmware installed IMG-01.4.1466



Added TAGs
[edited by: Raphael Alganes at 10:14 AM (GMT -7) on 22 Apr 2024]
Parents
  • Hello Alan,

    Thank you for contacting the Sophos Community.

    Does the issue persist? Is the NTP a local NTP (Local devices reaching our to Windows Server on a different zone) or a Public NTP?

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
  • No, the NTP are all public time servers. (ex.: time.windows.com, all public NIST time servers). The Sophos Firewall can contact time servers to update itself, but not any devices behind the switch.

    I have verified it was the issue after several tests. Disabling the DoS Prevention on sophos switch. then allows time synchronization.

    You can see from the screenshots, then time synchronization works with DoS disabled, then fails after turning DoS on.

    Screenshot 1: DoS Disabled

    Screenshot 2: DoS Enabled

  • No replies yet. Is this being looked into as the switch is blocking NTP? I assume it's blocking NTP as that is the network time protocol.

    This is a very severe usability problem if devices cannot update their time on the network when DoS prevention is enabled.

    I paid almost $500 for this switch, it is the stupidest purchase I ever made. I bought it when I had more devices and wanted to utilize inter-VLAN routing of my devices through the Sophos firewall, and the user GUI is much simpler than a Cisco switch.

    But blocking NTP is simply not acceptable.

Reply
  • No replies yet. Is this being looked into as the switch is blocking NTP? I assume it's blocking NTP as that is the network time protocol.

    This is a very severe usability problem if devices cannot update their time on the network when DoS prevention is enabled.

    I paid almost $500 for this switch, it is the stupidest purchase I ever made. I bought it when I had more devices and wanted to utilize inter-VLAN routing of my devices through the Sophos firewall, and the user GUI is much simpler than a Cisco switch.

    But blocking NTP is simply not acceptable.

Children