Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NTPd which interfaces

    Scheduled Pinned Locked Moved General pfSense Questions
    6 Posts 3 Posters 715 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      alan.t
      last edited by

      Hello,

      What exactly does “bind to” mean when selecting the interfaces for the pfSense NTPd to use ? I think I want it to listen on the WAN in order to get the time from the pool servers, but I don’t want it to serve the time to anything on the WAN. I want it to serve the time to all my local interfaces.

      Does that mean I select

      1. WAN only, or
      2. all interfaces except the WAN, or
      3. all interfaces

      I have seen all three possibilities recommended :)

      BRgds/Alan

      JKnottJ 1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott @alan.t
        last edited by

        @alan-t

        Where are you seeing that? I don't see any mention of ports or "bind to" You point the server to whatever sources and then clients on the LAN can connect to pfsense.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          It's mentioned on the linked help page from the config:

          Interface:
          
              Select the interface(s) to use for NTP. The NTP daemon binds to all interfaces by default to receive replies properly. This may be minimized by selecting at least one interface to bind, but that interface will also be used to source the NTP queries sent out to remote servers, not only to serve clients. Deselecting all interfaces is the equivalent of selecting all 
          

          Steve

          A 1 Reply Last reply Reply Quote 0
          • A
            alan.t @stephenw10
            last edited by

            @stephenw10 , thanks.

            Yes, I read the docs and the system is working fine. I guess I am trying to figure out what the best practice is.

            I have 9 VLANS all showing as an "Interface", plus WAN and localhost. It looks to me like I should select everything that I want to be served with the time, including localhost. However, it isn't clear what to do with the WAN - the docs appear to suggest that any interface could be used to contact the nominated time servers, in which case no need to select WAN ??

            BRgds/Alan

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              The default setting, where it uses all interfaces, is fine. Incoming traffic is blocked on WAN so nothing external can query it.

              Yes, if you don't select WAN ntpd cannot source from it to reach external servers. But that's fine, it can just use another interfaces and be NAT'd. Traffic is stil routed out of the WAN.

              Steve

              A 1 Reply Last reply Reply Quote 0
              • A
                alan.t @stephenw10
                last edited by

                @stephenw10 ... ah I see.

                Thanks everyone,

                BRgds/Alan

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.