but, I have one more question regarding NTP on the WAN side.
Wouldn't it be risky to allow my router to receive incoming requests on port 123 and forward them to OPNsense? like, wouldn't this expose the firewall to a DDoS?
I say this bc I'm in an enterprise environment and I don't really know what the standard practice is — should I do that and then implement a whitelist for the NTP pool servers or apply rate limiting on incoming NTP traffic?
Or is it generally recommended not to expose NTP to the Internet at all and just find a workaround?
Sorry if these are basic questions, I'm still junior :(
Wouldn't it be risky to allow my router to receive incoming requests on port 123 and forward them to OPNsense? like, wouldn't this expose the firewall to a DDoS?
I say this bc I'm in an enterprise environment and I don't really know what the standard practice is — should I do that and then implement a whitelist for the NTP pool servers or apply rate limiting on incoming NTP traffic?
Or is it generally recommended not to expose NTP to the Internet at all and just find a workaround?
Sorry if these are basic questions, I'm still junior :(
"