Juergen Beisert wrote:
> Why is port 123 open on eth0?

David Woolley writes:
> To allow the replies to come back in from the time servers.  ntpd
> sends UDP packets with both source and destination set to 123, not
> just when talking to peers.

With a stateful firewall it is only necessary to allow outgoing packets
on a port to establish a connection from inside.  The firewall will
recognize the reply packets as part of an established connection.
-- 
John Hasler 
[email protected]
Dancing Horse Hill
Elmwood, WI USA

_______________________________________________
questions mailing list
[email protected]
https://lists.ntp.org/mailman/listinfo/questions

Reply via email to