- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: Unexpected rejection of NTP traffic by URLF
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Unexpected rejection of NTP traffic by URLF
Can anyone tell me the reason I am seeing NTP traffic being bagged by the gateway?
NTP is not listed as the service associated with the Facebook and it is actually an Apple's service/domain:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Vladimir,
try the following:
1) Create a clone of the service ntp-udp
2) Enable "Protocol Signature"
3) Use the new service ntp-udp_Clone in the ruleset.
This limits the PSL analysis only to UDP port 123.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks @HeikoAnkenbrand , but this does not explain why it was rejected in the first place, which is what I am trying to figure out:)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Going to guess a bad signature got pushed out.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You may want to alert relevant team about his one: either apple or NTP bound to have issues...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hm...I see your point, thats very odd. Looking at your rule, it only shows app facebook,not any ntp services, so its not very logical as to why it would drop it on that rule. Did this just start happening recently or you ever noticed it before after you created the rule?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did not see it before, but then thi is a lab setup where I work out some issues for the clients or trying things out for myself. This gem manifested only after said rule was created.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Vladimir,
I have contacted you in a private message which will help better understand your case. To my current understanding, the NTP detection worked as expected, but more details regarding your case and environment may be needed. Let's continue this offline
Thanks,
Avi
