Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

LAN Clients unable to receive External NTP Server Time

Hello,

Recently moved from UTM to XG and I'm encountering an issue where my LAN clients are unable to receive NTP replied from NTP servers.  I did not have this issue in UTM.

My general rule setup is to allow any LAN client unrestricted access to the internet.  When viewing the logs, port 123 traffic is allowed outbound, but does not appear that any client is recieiving the reply.  I have no other known issues connecting to the internet for any other services.  The Sophos XG appliance is able to get accurate time from NTP servers.

Are there any configurations I should be making to allow NTP for the LAN clients?

Thanks!

Brad



This thread was automatically locked due to age.
Parents
  • I had to create a specific firewall rule for this-

     

    Source - LAN

    Device - ANY  (You can define this more)

    Destination - WAN

    Device - the location you are pulling NTP from ex ntp.pool.org enter as IP or FQDN (host name)

    Service - NTP

     

    Then place at the top, you do not need protection for this since it will only allow to the specific destination, on the specific port.

     

    Respectfully, 

     

    Badrobot

     

Reply
  • I had to create a specific firewall rule for this-

     

    Source - LAN

    Device - ANY  (You can define this more)

    Destination - WAN

    Device - the location you are pulling NTP from ex ntp.pool.org enter as IP or FQDN (host name)

    Service - NTP

     

    Then place at the top, you do not need protection for this since it will only allow to the specific destination, on the specific port.

     

    Respectfully, 

     

    Badrobot

     

Children
No Data