networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 5 posts ] 
Author Message
 Post subject: ASA NTP Configuration
PostPosted: Mon Apr 02, 2012 6:20 am 
Offline
New Member
New Member
User avatar

Joined: Fri Jun 24, 2011 7:22 am
Posts: 37
Location: Stevenage, UK
Certs: CCNA, CCVA
I have a Server that is going to be communicating to uk.pool.ntp.org for its time, but obviously i need to configure this in the ASA to allow it access

I dont have a list of IPs in that pool and i cant find them on the internet either

So how would you get around this?


Top
 Profile  
 
PostPosted: Mon Apr 02, 2012 6:31 am 
Offline
Junior Member
Junior Member
User avatar

Joined: Tue Feb 15, 2011 3:19 am
Posts: 61
Certs: MCSE, CCNA, CCNP, CCSP, CCNP Security
If it's the NTP server IP addresses that you are unsure of, have you tried enabling logging in ASDM and monitoring which IPs it's trying to connect to?

_________________
Isuru Senadheera
MCSE, CCNP, CCSP, MCITP
www.isururakshitha.org


Top
 Profile  
 
PostPosted: Mon Apr 02, 2012 8:47 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Fri Apr 25, 2008 2:16 pm
Posts: 1361
Location: Jacksonville, FL
Certs: CCNP, CCNA:Sec, MCSE
The list is likely large, and fairly dynamic; you may need to attack this problem a different way (such as pointing the server toward a few members of that pool but not the whole pool).

_________________
"A problem well stated is a problem half solved". (Charles Kettering)


Top
 Profile  
 
PostPosted: Mon Apr 02, 2012 9:40 am 
Offline
Ultimate Member
Ultimate Member

Joined: Wed Sep 01, 2010 3:37 pm
Posts: 907
Location: Las Vegas, NV
Certs: Sec+, MCSE, MCITP:EA, CCNP
Can't you do an nslookup to get the IPs? Of course the pool list is probably changing on a regular basis. I would just do as Dinger said, and point to a few IPs in the list.

-Otanx


Top
 Profile  
 
PostPosted: Mon Apr 02, 2012 12:03 pm 
Offline
Member
Member

Joined: Sun Apr 17, 2011 3:28 pm
Posts: 213
Certs: CCSP/CCNP:Security GIAC GPEN
I believe FQDN support was added in 8.4.2 for objects and can be used in ACLs but I honestly have no idea if it will actually do a DNS look up and permit traffic based on that. Never tested using FQDNs with ACLs.

*EDIT*

Looks like it might actually work for what you want. There are a few caveats to using FQDNs so make sure you read the limitations section in the link.

https://supportforums.cisco.com/docs/DOC-17014

_________________
The Cubicle Wizard
http://cubiclewizard.blogspot.com/


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 5 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: Google Feedfetcher and 9 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group