Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Routing NTP traffic from PFsense through VPN.

    Scheduled Pinned Locked Moved OpenVPN
    6 Posts 4 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pereira
      last edited by

      I'm stuck with an ISP that has blocked port 123 both ways for us (long story), so I'm attempting to get the time through VPN.

      The VPN connection works fine and I was able to route all LAN originated NTP through the VPN connection. I would like however to have all machines on LAN to get the time from PFsense and let PFsense get the time from internet.

      So far the only way I got to work was by adding a static route to the IP of a NTP server. This will likely break if the IP should change though.

      Is it at all possible to somehow route only firewall originated NTP traffic through the VPN connection (without manually adding a static route)? I've tried floating rules with a source of This Firewall, but that didn't work after numerous attempts.

      1 Reply Last reply Reply Quote 0
      • jahonixJ
        jahonix
        last edited by

        Use a local GPS receiver and connect that to your pfSense
        https://forum.pfsense.org/index.php?topic=101498.msg566360

        On the next occasion kick your ISP's butt.

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          Good advice ^

          There are many ways to run a ntp server on inexpensive hardware - I run a stratum 1 on raspberry pi with addon gps board.  Total cost was less then $100.. Pi, case, power supply, sd card, add on board, antenna.. Can be done even cheaper for sure..

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          1 Reply Last reply Reply Quote 0
          • jahonixJ
            jahonix
            last edited by

            https://forum.pfsense.org/index.php?topic=132167.0

            1 Reply Last reply Reply Quote 0
            • P
              pereira
              last edited by

              I'll take that as a no (to being able to do it with policy based routing) then. :D

              Thanks all.

              1 Reply Last reply Reply Quote 0
              • K
                kpa
                last edited by

                If setfib(1) was usable on pfSense and integrated to the GUI so that the FIBs could be managed easily you could use them for policy routing but only based on the destination addresses which would be fine assuming the NTP peers are known and don't change. This would of course require integration with the OpenVPN start/stop events to properly hook the custom FIBs when appropriate.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.