Community discussions

MikroTik App
 
User avatar
paolopoz
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 77
Joined: Thu Oct 31, 2013 6:38 pm

SNTP client get unauthorized NTP requests

Thu Jan 11, 2018 4:51 pm

I have some routers with SNTP client (the built-in one) enabled and working.
Some interfaces has public IP addresses but I don't have any firewall rule configured because I want to use FastPath.

Checking SNTP client status I often see this:
  last-bad-packet-from: 162.209.xxx.xx
  last-bad-packet-before: 6m43s410ms
  last-bad-packet-reason: server-ip-mismatch
I had a packet capture and I saw that these packets are NTP requests coming in, as if the router was listening on port 123.
I think this should not happen. Has anybody noticed this?
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: SNTP client get unauthorized NTP requests

Thu Jan 11, 2018 5:31 pm

Those are people scanning the internet for all kinds of services to see if there is something they can abuse.
Whenever you have an open connection to internet you will see this, it is often called the background noise.
 
User avatar
paolopoz
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 77
Joined: Thu Oct 31, 2013 6:38 pm

Re: SNTP client get unauthorized NTP requests

Thu Jan 11, 2018 5:54 pm

Thanks pe1chl, this is of course some kind of scanning coming from big internet but this is not what I want to point out.

What I mean is: a client should just get back its request, then why do I see incoming packets as if the router was listening on port 123/UDP? This is a server behaviour.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: SNTP client get unauthorized NTP requests

Thu Jan 11, 2018 7:39 pm

With UDP it is not possible to see the difference between a request and a reply.
(and to receive replies, you need to listen on a socket which you also use to send requests)
When you let in replies, you also let in requests.
That is why stateful firewalls exist....
 
User avatar
16again
Frequent Visitor
Frequent Visitor
Posts: 78
Joined: Fri Dec 29, 2017 12:23 pm

Re: SNTP client get unauthorized NTP requests

Thu Jan 11, 2018 7:52 pm

no firewall rules in forward chain for fastpath ....is sort of OK
But this shouldn't rule out firewall rules in in-chain (which isn't fst-pathed to begin with)

@ pe1chl
The 1st UDP packet is in my definition the request, I we block it in in-chain, there will be no reply

Who is online

Users browsing this forum: ridict and 17 guests