<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Open port 123 for Ubiquiti NTP access</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/148046/open-port-123-for-ubiquiti-ntp-access</link><description>Hi all, 
 I have a XG135 firewall and several RED devices, I also have several devices from Ubiquiti (UNVR and CloudKeys) and they are causing problems. Ubiquiti support keeps telling me that I need to allow access on UDP port 123 which they use for NTP</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Open port 123 for Ubiquiti NTP access</title><link>https://community.sophos.com/thread/548896?ContentTypeID=1</link><pubDate>Thu, 21 Nov 2024 12:42:14 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:8e182565-74fe-49e2-9f43-8331b3584107</guid><dc:creator>LHerzog</dc:creator><description>&lt;p&gt;the Unifi devices will connect to the NTP servers defined in the Network server / controller.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;img alt=" " src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pastedimage1732192772478v2.png" /&gt;&lt;/p&gt;
&lt;p&gt;That&amp;#39;s what you need to allow&lt;/p&gt;
&lt;p&gt;Unifi devices do not need NTP before they register at the Network server. After they register, they will use the time servers defined by you there.&lt;/p&gt;
&lt;p&gt;Unifi devices will ignore NTP servers that you set as DHCP option (41).&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Open port 123 for Ubiquiti NTP access</title><link>https://community.sophos.com/thread/548895?ContentTypeID=1</link><pubDate>Thu, 21 Nov 2024 12:30:29 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:d3c53cba-0e6f-41f9-93da-2cbff0c3fba8</guid><dc:creator>RickWeiss</dc:creator><description>&lt;p&gt;I have used the following Sophos Recommended Read to allow NTP access for all my internal devices.&amp;nbsp; It has worked well for the last couple of years.&lt;/p&gt;
&lt;p&gt;I used Option 1 and chose to use us.pool.ntp.org but you can use what ever ntp source is appropriate for your location.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;a href="/sophos-xg-firewall/f/recommended-reads/118433/sophos-firewall-using-nat-to-achieve-ntp-proxy-like-functionality"&gt;https://community.sophos.com/sophos-xg-firewall/f/recommended-reads/118433/sophos-firewall-using-nat-to-achieve-ntp-proxy-like-functionality&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Open port 123 for Ubiquiti NTP access</title><link>https://community.sophos.com/thread/548874?ContentTypeID=1</link><pubDate>Thu, 21 Nov 2024 07:34:51 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:9a831fde-2326-4f1c-8aad-84d208417f98</guid><dc:creator>rfcat_vk</dc:creator><description>&lt;p&gt;Please try adding a UDP for NTP to the service definition.&lt;/p&gt;
&lt;p&gt;Ian&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Open port 123 for Ubiquiti NTP access</title><link>https://community.sophos.com/thread/548869?ContentTypeID=1</link><pubDate>Thu, 21 Nov 2024 04:25:50 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:65f93413-2621-4ba2-95f9-056b4bab725f</guid><dc:creator>Erick Jan</dc:creator><description>&lt;p&gt;Hi MCBLC,&lt;/p&gt;
&lt;p&gt;Thank you for reaching out to Sophos Community.&lt;/p&gt;
&lt;p&gt;I recommend checking the logs and performing a packet capture/TCPDump to gain more insight into what has happened to the traffic.&lt;/p&gt;
&lt;p&gt;&lt;span&gt;You may also create&amp;nbsp;an allow firewall rule and position the rule on top without any other policies&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Kindly check the following links and similar posts.&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.sophos.com/nsg/sophos-firewall/21.0/help/en-us/webhelp/onlinehelp/AdministratorHelp/RulesAndPolicies/FirewallRules/FirewallRuleAdd/index.html"&gt;Add a firewall rule&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&amp;nbsp;&lt;a href="https://community.sophos.com/sophos-xg-firewall/f/discussions/141584/allow-port-in-sophos-firewall"&gt;Allow Port in Sophos Firewall&lt;/a&gt;&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>