Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Running NTP Server on pfSense

    Scheduled Pinned Locked Moved General pfSense Questions
    3 Posts 3 Posters 379 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      ericnix
      last edited by

      I have my pfSense box running OpenVPN and serving as my DDNS relay. I'm also running Snort on it. My primary router is a Ubiquiti router.

      I noticed a setting for an NTP server while messing around with the pfSense web configurator.

      What is the advantage of running an NTP server within your own network?

      My pfSense box is configured as 10.0.1.90. The router handles DHCP (I previously had used the pfSense box to handle it). If I were to configure the NTP server, do I put 10.0.1.90 as the NTP server on computers, Ubiquiti LAN configuration, etc.?

      JKnottJ 1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott @ericnix
        last edited by

        @ericnix

        You could have your own stratum 0 server, such as a GPS receiver. Also, good practice is to have local servers to reduce the load on upstream servers. The more a server handles, the less precision it can provide.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        N 1 Reply Last reply Reply Quote 0
        • N
          netblues @JKnott
          last edited by

          In addition to that, there have been amplification attacks based on ntp. So using an external service increases your attack surface in any future possible breach attempts.

          Best security practices dictates to use as less external services as possible.
          Same goes for dns and forwarders.

          (and the beauty of running a stratum 0 ntp server, over pps, remains with the few who have attempted the task.
          Now, I wish datacenters had glass roofs so gps could work on top of racks.. :)

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.