• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

NTP server, no localhost?

Scheduled Pinned Locked Moved General pfSense Questions
7 Posts 4 Posters 899 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Q
    q54e3w
    last edited by Mar 15, 2020, 9:52 PM

    Why is there no ability to select localhost in the NTP server settings? I wanted to configure my firewall to only listen on a specific set of subnet and the localhost for any redirects. The only way appears to enable all interfaces as a wildcard which enables the localhost.
    In the DNS resolver I can select localhost so assumed I would have been able to for NTP too.
    Would like to understand why not if theres a reason for the difference.
    Verified behavior in 2.4.4 and 2.4.5-RC.

    J 1 Reply Last reply Mar 15, 2020, 10:00 PM Reply Quote 0
    • J
      JKnott @q54e3w
      last edited by Mar 15, 2020, 10:00 PM

      @q54e3w

      ????

      You're supposed to configure NTP to use a server that's closer to International Atomic Time. Other than using a computer's hardware clock, I have never heard of using anything other than NTP servers as a source. Once you have a NTP server running, you can have other devices use it.

      On my network, I have pfSense pointing to 4 pool.ntp.org servers. At work last year, I was working on a project where they had 2 GPS receivers for NTP stratum 0 servers.

      PfSense running on Qotom mini PC
      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
      UniFi AC-Lite access point

      I haven't lost my mind. It's around here...somewhere...

      1 Reply Last reply Reply Quote 0
      • Q
        q54e3w
        last edited by q54e3w Mar 15, 2020, 10:10 PM Mar 15, 2020, 10:06 PM

        I have several local GPS/PPS time based servers including a LeoNTP that pfSense syncs to. I wanted to ensure that any devices that are hardcoded to use external NTP servers are redirected back to my firewall for time.
        EDIT: for example, Chinese security cameras, Android, Amazon FireTV devices etc.

        J 1 Reply Last reply Mar 15, 2020, 10:12 PM Reply Quote 0
        • J
          JKnott @q54e3w
          last edited by Mar 15, 2020, 10:12 PM

          @q54e3w

          That is not the way I read your question. I suspect you may want to redirect the NTP requests you your own address, not make the pfSense NTP server use the localhost address.

          PfSense running on Qotom mini PC
          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
          UniFi AC-Lite access point

          I haven't lost my mind. It's around here...somewhere...

          1 Reply Last reply Reply Quote 0
          • K
            kiokoman LAYER 8
            last edited by kiokoman Mar 15, 2020, 10:54 PM Mar 15, 2020, 10:14 PM

            select the interfaces you need, start ntp server and
            you can port forward to intercept any traffic that try to go out through NTP port and redirect to, for example "LAN/OPT address" (which represent the ip of pfsense for that interface) or another ntp server
            Immagine1.jpg

            Immagine2.jpg

            take in mind that NAT rules are evaluated before firewall rules so all other rules i'm showing will never apply, in this example only the one with NAT under description will match the traffic

            ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
            Please do not use chat/PM to ask for help
            we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
            Don't forget to Upvote with the 👍 button for any post you find to be helpful.

            1 Reply Last reply Reply Quote 0
            • S
              stephenw10 Netgate Administrator
              last edited by Mar 16, 2020, 1:37 AM

              Hmm, yeah not sure why localhost isn't an option there. As you say the only way to select it is through 'all interfaces'.

              You could open a feature request if one does not already exist:
              https://redmine.pfsense.org/

              Steve

              1 Reply Last reply Reply Quote 0
              • Q
                q54e3w
                last edited by Mar 16, 2020, 1:49 AM

                Thanks Steve. I don't see one so created one under Issue #10348.

                1 Reply Last reply Reply Quote 0
                1 out of 7
                • First post
                  1/7
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                  This community forum collects and processes your personal information.
                  consent.not_received