<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ntp-tcp-Protocol-Signature Traffic in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ntp-tcp-Protocol-Signature-Traffic/m-p/209248#M39641</link>
    <description>&lt;P&gt;Maybe a screenshot of 1 log entry?&lt;/P&gt;
&lt;P&gt;Also maybe you made a custom application at one point that now is matching?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk103051" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk103051&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Mar 2024 09:10:29 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2024-03-20T09:10:29Z</dc:date>
    <item>
      <title>ntp-tcp-Protocol-Signature Traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ntp-tcp-Protocol-Signature-Traffic/m-p/208945#M39575</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have checkpoint r81.10 gateway and in my firewall log I get a lot of "ntp-tcp-Protocol-Signature Traffic" dropped traffic what is this service used for please help if it is a legit or not ?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Mar 2024 23:49:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ntp-tcp-Protocol-Signature-Traffic/m-p/208945#M39575</guid>
      <dc:creator>Ihenock1011</dc:creator>
      <dc:date>2024-03-17T23:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: ntp-tcp-Protocol-Signature Traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ntp-tcp-Protocol-Signature-Traffic/m-p/208971#M39581</link>
      <description>&lt;P&gt;Who is sending this traffic ? NTP uses UDP, so the drop is understandable...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 08:53:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ntp-tcp-Protocol-Signature-Traffic/m-p/208971#M39581</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-03-18T08:53:35Z</dc:date>
    </item>
    <item>
      <title>Re: ntp-tcp-Protocol-Signature Traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ntp-tcp-Protocol-Signature-Traffic/m-p/209004#M39596</link>
      <description>&lt;P&gt;Users which is allowed internet access&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 12:56:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ntp-tcp-Protocol-Signature-Traffic/m-p/209004#M39596</guid>
      <dc:creator>Ihenock1011</dc:creator>
      <dc:date>2024-03-18T12:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: ntp-tcp-Protocol-Signature Traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ntp-tcp-Protocol-Signature-Traffic/m-p/209037#M39606</link>
      <description>&lt;P&gt;I would suggest to contact CP TAC to get an explanation!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 15:23:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ntp-tcp-Protocol-Signature-Traffic/m-p/209037#M39606</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-03-18T15:23:07Z</dc:date>
    </item>
    <item>
      <title>Re: ntp-tcp-Protocol-Signature Traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ntp-tcp-Protocol-Signature-Traffic/m-p/209041#M39608</link>
      <description>&lt;P&gt;NTP is used to synchronize clocks with a trusted time source, but it generally happens over UDP, not TCP.&lt;BR /&gt;A snapshot of the log card (with sensitive details redacted) would be helpful.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 16:19:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ntp-tcp-Protocol-Signature-Traffic/m-p/209041#M39608</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-03-18T16:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: ntp-tcp-Protocol-Signature Traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ntp-tcp-Protocol-Signature-Traffic/m-p/209240#M39640</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;kindly find the screenshot&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ntp.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24948iE1C448DB649E4543/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ntp.jpg" alt="ntp.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 07:33:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ntp-tcp-Protocol-Signature-Traffic/m-p/209240#M39640</guid>
      <dc:creator>Ihenock1011</dc:creator>
      <dc:date>2024-03-20T07:33:53Z</dc:date>
    </item>
    <item>
      <title>Re: ntp-tcp-Protocol-Signature Traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ntp-tcp-Protocol-Signature-Traffic/m-p/209248#M39641</link>
      <description>&lt;P&gt;Maybe a screenshot of 1 log entry?&lt;/P&gt;
&lt;P&gt;Also maybe you made a custom application at one point that now is matching?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk103051" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk103051&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 09:10:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ntp-tcp-Protocol-Signature-Traffic/m-p/209248#M39641</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-03-20T09:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: ntp-tcp-Protocol-Signature Traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ntp-tcp-Protocol-Signature-Traffic/m-p/209281#M39644</link>
      <description>&lt;P&gt;That's not a full log card, open up one of the log entries and send a screenshot (again with sensitive details redacted).&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 14:03:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ntp-tcp-Protocol-Signature-Traffic/m-p/209281#M39644</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-03-20T14:03:04Z</dc:date>
    </item>
  </channel>
</rss>

