NTP server issues
-
So you have a vip on igb1?
I would sniff on your wan - do you see traffic going out to those servers? With source IP natted to your wan IP?
Is your default route out your wan, or via vpn.. IE you pulled routes?
-
@johnpoz if you mean the 10.10.10.1 it is coming from pFBlocker - i am disabling that and snort to check the effect
-
Snort huh... yeah could be problematic..
But its a given if your ntpd can not get into sync by talking to the ntp servers you point it to, either direct or pool then no clients would sync with it. ;) since its not a valid time source until it has gotten into sync with valid time source.
-
thanks guys for all the help. I found the answer in here.
https://forum.netgate.com/topic/131506/ntp-not-working-solved-totally/27by jimp Rebel Alliance Developer Netgate Jun 21, 2018, 5:27 PM
Firewall > NAT, Outbound tab. Add rule to top.
Disabled: Unchecked
Do not NAT: Unchecked
Interface: WAN (make one of these rules for each WAN)
Protocol: any
Source: This Firewall (self)
Destination: any
Not: Unchecked
Translation Address: Interface Address
Port or Range: Blank
Description: NAT anything out from the firewall itself -
So the problem was I thought you were not natting.. Which prob has something to do with manual nats and all your vpn interfaces...