Florin Andrei wrote:
> Yeah, anything along the general lines of the proposals
>  above would be great. Would have saved me a lot of trouble.

restrict source ...
 has been around since ntp 4.2.7p22 (01-Apr-2010)?

 However you are using ntp 4.2.2p1-7 (08-Jul-2006) ?


> server 10.10.16.65 iburst
> server 10.10.16.64 iburst
>
> # excepting the servers from more drastic restrictions
> restrict 10.10.16.64 noquery
> restrict 10.10.16.65 noquery

So, those server can't get time from yours,
 but they can change your running conf and request to be a trap?


> # allow local queries
> restrict 127.0.0.0 mask 255.0.0.0
>
> # now close the door
> restrict default ignore
>

I would have done it in the opposite order,
 (default ignore, before allows), perhaps it doesn't matter.


-- 
E-Mail Sent to this address <[email protected]>
  will be added to the BlackLists.

_______________________________________________
questions mailing list
[email protected]
http://lists.ntp.org/listinfo/questions

Reply via email to