12-20-2016 7:19 AM
I have a Pace 5268AC and have my own router behind it using DMZplus. The firmwware is versions are:
I can't get any devices to sync time using NTP. This includes laptops, desktops, Raspberry Pis and other devices. This is causing me no end of issues as with devices so far out of sync SSL certs fail checks, services on Linux boxes hang etc.
I have searched everywhere and found references to others having issues but haven't found any soltuions. I have tried factory resetting the 5268AC and tried adjusting the "Strict UDP Session Control" setting in the Advanced firewall tab.
I find it hard to accept that no gigapower users are allowed to sync time, am I missing something? Is this a bug in the 5268AC? Any help would be very much appreciated.
03-02-2018 2:13 PM
to set this up on Mikrotik, you need
src port (NOT dst port) 123
Minor nit: IANA recommends 49152 to 65535 ephemeral ports. If you're going to rewrite the packet may as well do it with best practices in mind.
08-03-2018 2:12 PM
Late to the party here, but with some datapoints for general reference.
I have ATT uVerse as provided by a reseller (sonic.net). My router is NVG589.
I run ntpsec.anastrophe.com stratum 1 on a Raspberry Pi. I have other servers on my network, so I'm just using NAT. I have numerous peers and clients. All traffic is source port 123, destination port 123.
Regular client applications cannot connect to my server, because they use unprivileged source ports. This traffic is being blocked upstream of me - from an offsite server:
13:40:23.790824 IP 10.125.75.117.49155 > 18.104.22.168.123: NTPv4, Server, length 3
13:40:31.087135 IP 10.125.75.117.49155 > 22.214.171.124.123: NTPv4, Server, length 3
13:40:31.123334 IP 126.96.36.199 > 10.125.75.117: ICMP host 188.8.131.52 unreachable - admin prohibited filter, length 76
13:40:57.974002 IP 10.125.75.117.65000 > 184.108.40.206.123: NTPv4, Server, length 3
13:40:58.010980 IP 220.127.116.11 > 10.125.75.117: ICMP host 18.104.22.168 unreachable - admin prohibited filter, length 76
Kind of a pain, but since I'm primarily interested in peering stratum 1, it's only a small population that's affected (though it would be nice if they could connect too).
Maybe this will help someone.
08-03-2018 3:59 PM
Visit these related resourcesView New Device Help!