|
Question : setting NTP on PIX 501
|
|
Here is the current config for the pix. What do I need to adjust or add to make the ntp sync work?????
ip address outside 81.178.60.201 255.255.255.248on 710005: UDP request discarded from 192.168.1 ip address inside 192.168.1.170 255.255.255.0l debugging, 2578 messages logged900 8.1.115 ip audit name checkit attack action alarm reset5: UDP request discarded from 192.168.1.142/138 ip audit interface outside checkit135.200.29:/rtm?RtmCm Buffer l ip audit info action alarm78 messages bios-dgmo out ip audit attack action alarmrded from 192.168.1.103/138 ip audit signature 2000 disablend UDP connec History loggi ip audit signature 2001 disable:12eue ccess-list outside_access_in permit ip host YMA_Associates anyr outside:217.163.17.194/443 (217.16uration 0:00:01 bytes 2724 access-list inside_outbound_nat0_acl permit ip any 192.168.1.180 255.255.255.252.168.1.144/3183 (81.178.60.202/3183)of available commands.connection 468 for out
access-list outside_cryptomap_dyn_20 permit ip any 192.168.1.180 255.255.255.252/443 to inside:192 for a list of available commands.all(config)# 111009: User 'i
access-list external deny ip any anyation 0:00:01 bytes 1329 TCP FINsard timeout xlate 3:00: 68.1.115/2044 d 3020 aaa-server LOCAL protocol localUDP request discarded from 192. filter activex 80 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0586 for outside:65.205.8.63/80 to i 304001: .168. filter java 80 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0bound TCP connection 655 for outside:62.241.16 ntp authentication-key 1234 md5 ********lation from inside:192.168.1.115/2070 to ntp authenticate.163.103/110) to ntp trusted-key 1234/3189 (81.178.60.202 http server enable178.60.201/1252 du http YMA_Associates 255.255.255.255 outside 710005: UDP request di no snmp-server enable traps37 to inside:192.168.1.255/ virtual telnet 192.168.1.48.161/80 (213.160s 19521 T floodguard enable63.17.194/44 bios sysopt connection permit-ipsecnd UDP connection 656 for outs auth-prompt prompt full body cavity search for outside:216.113 302014: Teardown TCP
crypto dynamic-map outside_dyn_map 20 match address outside_cryptomap_dyn_20 ins isakmp policy 20 hash md5 isakmp policy 20 group 2 isakmp policy 20 lifetime 86400 vpngroup RemoteUsers address-pool VPN vpngroup RemoteUsers dns-server 158.43.240.3 158.43.240.4 vpngroup RemoteUsers idle-time 1800 vpngroup RemoteUsers password ******** telnet YMA_Associates 255.255.255.255 outside telnet 0.0.0.0 0.0.0.0 inside telnet timeout 60 ssh 192.168.1.113 255.255.255.255 inside ssh timeout 5 console timeout 0 vpdn username kae password ******** vpdn username capistrano password ******** vpdn enable outside vpdn enable inside
|
Answer : setting NTP on PIX 501
|
|
The NTP server is the IP address of the NTP server that you are trying to authenticate with. It is not your own IP address. Static, dynamic, means nothing. The NTP server will have one IP address and it won't be your own. You must have set up your own NTP server with the authentication key, so you must know its IP address.
|
|
|