DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
2860n - need to block NTP 123 from outside
- peterg22
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 16
- Thank yous received: 0
26 Jul 2017 08:48 #89308
by peterg22
2860n - need to block NTP 123 from outside was created by peterg22
Hi All:
Vigor 26860n Firmware version 3.8.4.3_BT FTTC Zen
The other day my ISP informed me that my IP address had been used in an NTP amplification attack and "would I please fix it? ".
I run a Raspberry Pi as a Stratum 1 time server
http://www.satsignal.eu/ntp/Raspberry-Pi-NTP.html
and the intention was that this would only be used by my small internal network. However, this turned out not to be the case and was due to my misconfiguration.
I believe I've now closed off port 123 to external users using firewall rules, but when I run the nmap monlist script I get the port as open but filtered. My NTP software is apparently not vulnerable (Ver. 4.2.8p10)
nmap -sU -pU:123 -Pn -n --script=ntp-monlist xx.xx.xx.xx
If i then run the recommended test using ntpdc I get a different answer:
ntpdc -c monlist xx.xx.xx.xx
And finally, as if to add another level of confusion, my entry on shodan.io shows port 123 as open!
Can I please get some advice?
TIA
Vigor 26860n Firmware version 3.8.4.3_BT FTTC Zen
The other day my ISP informed me that my IP address had been used in an NTP amplification attack and "would I please fix it?
I run a Raspberry Pi as a Stratum 1 time server
I believe
Code:
Starting Nmap 6.47 ( http://nmap.org ) at 2017-07-26 08:35 BST
Nmap scan report for xx.xx.xx.xx
Host is up.
PORT STATE SERVICE
123/udp open|filtered ntp
Nmap done: 1 IP address (1 host up) scanned in 7.07 seconds
If i then run the recommended test using ntpdc I get a different answer:
Code:
xx.xx.xx.xx: timed out, nothing received
***Request timed out
And finally, as if to add another level of confusion, my entry on shodan.io shows port 123 as open!
Can I please get some advice?
TIA
Please Log in or Create an account to join the conversation.
- lorian
- Offline
- Member
Less
More
- Posts: 190
- Thank yous received: 0
29 Jul 2017 23:18 #89332
by lorian
Replied by lorian on topic Re: 2860n - need to block NTP 123 from outside
In your inbound rule rather than blocking packets, drop them.
Please Log in or Create an account to join the conversation.
- peterg22
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 16
- Thank yous received: 0
30 Jul 2017 10:12 #89335
by peterg22
Thanks - however, on the 2860n I ony have "pass" and "block" as options. Or, did you mean on iptables/UFW on the actual server itself?
Replied by peterg22 on topic Re: 2860n - need to block NTP 123 from outside
In your inbound rule rather than blocking packets, drop them.Lorian wrote:
Thanks - however, on the 2860n I ony have "pass" and "block" as options. Or, did you mean on iptables/UFW on the actual server itself?
Please Log in or Create an account to join the conversation.
- lorian
- Offline
- Member
Less
More
- Posts: 190
- Thank yous received: 0
30 Jul 2017 18:41 #89339
by lorian
Replied by lorian on topic Re: 2860n - need to block NTP 123 from outside
Ah, stop forwarding port 123 to your internal network altogether. You will have defined it in port redirection I guess.
Please Log in or Create an account to join the conversation.
Moderators: Chris
Copyright © 2025 DrayTek