Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PFSense as public NTP server

    Scheduled Pinned Locked Moved General pfSense Questions
    8 Posts 4 Posters 4.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      krisken
      last edited by

      Dear,

      I know PFSense has a NTP server on board for internal use.  But i want to set my pfsense server as a part of the NTP Pool project.  Do i just have to open port TCP 123 or do i have to do more?

      Kris

      1 Reply Last reply Reply Quote 0
      • J
        joebobfrank
        last edited by

        I believe that you will have to open up port 123 on the WAN and also enable OpenNTP to run on the WAN.

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          openntp not really a good choice as ntp server imho.  Not good way to monitor what its doing with ntpq or ntpdc, etc. like you can with the full ntp client.  Its ok for keep some boxes time somewhat correct.

          If you want to join the pool, just run full ntp on your pfsense box.  Simple enough to do.  This is what I did before I moved to virtual, now I use ntp on the actual host hardware as the ntp server vs the pfsense box.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • K
            krisken
            last edited by

            @joebobfrank:

            I believe that you will have to open up port 123 on the WAN and also enable OpenNTP to run on the WAN.

            I did that, but when i want to add the IP to the pool project, i get the error "Your servers hostname or IP address:Didn't get an NTP response from my.IP.address".

            firewallrule.jpg_thumb
            firewallrule.jpg
            ntpserver.jpg
            ntpserver.jpg_thumb

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              Is your WAN address really 10.0.0.1?
              Is weepee01 your WAN interface?

              Steve

              1 Reply Last reply Reply Quote 0
              • K
                krisken
                last edited by

                @stephenw10:

                Is your WAN address really 10.0.0.1?
                Is weepee01 your WAN interface?

                Steve

                10.0.0.1 is my PFSense box (internal IP)
                WAN interfaces are WeePee01 and EDPnet01 (dual wan setup)

                natntp.jpg
                natntp.jpg_thumb
                firewallrulesntp.jpg
                firewallrulesntp.jpg_thumb

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  You are port forwarding incoming ntp traffic to the pfSense LAN interface but you are running ntpd on WAN and not LAN.
                  Either enable ntpd on LAN as well (hold ctrl to select more interfaces) or remove the port forward and just set the firewall rule to the WAN interface.

                  Similarly there is no need to port forward to the LAN interface for webGUI access. Just open a firewall hole to WAN.

                  Steve

                  1 Reply Last reply Reply Quote 0
                  • K
                    krisken
                    last edited by

                    Quite a stupid mistake!  But indeed, it's working now!
                    Thanks a lot!

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.