william carlson wrote:
>Yes, When I got the first email I thought perhaps it was spoofed since >UDP traffic has no "handshake". But I have since patched together that >it is only sonicwall firewalls that generate these alerts. I am just >checking that there is not something misconfigured on my NTP server. >These are the log messeges that get sent to me > >[snip] > > >Since the source is 123 and every time they have verified they use >pool.ntp.org I assume it is some type of NTP issue on the client or poor >firewall code(more likely). I have asked the latest guy who emailed me >what he has for OS/NTP software. >Thanks, >Will > >- > > > I had a weird instance a while back where I had one of my FreeBSD boxes listening for ntp on an aliased IP and it would reply from the default IP for the interface which caused thing to a) not work and b) triggered firewall alerts from a bunch of clients. If you have multiple IP's on your box you might want to check you're not seeing the same thing. John _______________________________________________ timekeepers mailing list [email protected] https://fortytwo.ch/mailman/cgi-bin/listinfo/timekeepers
