NTP controls do not work

Started by someone, October 06, 2024, 07:20:55 PM

Previous topic - Next topic
The controls under NTP do not work
1. With only one ntp server checked and the others disabled I get twenty ntp queries every 5 to 10 seconds
2. With checking ntp check the network time once, doesnt change anything
If NTP stopped altogether the system will not startup, other words we cannot enter our own time to start the system
Opnsense would not accept system time
3. Far to much bandwidth for NTP
average 10 hits a second
not counting why are opnsense ntp servers sending a querie to my computer which is not ntp related
4. Ntp servers are queried which is not in an opnsense pool
5. I do not need a pool of servers

Maybe they do, I managed to completely stop it
Now to figure out how to slow it way down

Please show your settings.
Please show those queries.

It's impossible to help you with just some vague prose statements. NTP works perfectly as configured on >10 OPNsense installations for me.
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

Thank you my fault
Controls work, I again have a learning curve
I currently have them shut down completely for testing purposes and threat hunting
Thank you

I should say I learned how to tone down the amount of opnsense NTP traffic or shut it off altogether

Why would you shut down NTP? Synchronised time is essential in any network.
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

November 14, 2024, 06:02:53 AM #6 Last Edit: November 14, 2024, 06:04:39 AM by someone
1, Uncontrolled DNS causing uncontrolled NTP
2. To much bandwidth to monitor packets, must turn off for that
when I say uncontrolled we are talking 100 NTP server requests every 10 to 15 seconds
3. Working on usb GPS for time
4. Better security with one less port, and one less attack
5. Some power outages opnsense locks up gui,
could be my computer, but must ssh in and set date and time
which isnt difficult, not sure if gps would sync, havnt got that far yet
in a perfect world it would be fine

NTP is ok, but I have different circumstances here
onslaught of attacks including NTP ports and fake servers
Thanks