Link to home
Start Free TrialLog in
Avatar of Educad
EducadFlag for Australia

asked on

NTP port 123 outbound traffic

Hi,

I have been monitoring too many NTP traffic going out through Sophos firewall and they are all blocked by default. The destination of the outbound traffic is many different NTP server location not only one server.

Client PCs are trying to get time information from many locations, how can I make PCs to get their time information from internal NTP server rather external NTP server?

This is the list of IP address that internal PCs are trying to reach to get time information.

207.57.100.235 grapeofwrath.com.au
128.138.141.172 utcnist2.colorado.edu
24.56.178.140 host-24-56-178-140.beyondbb.com
64.113.32.5 nist.netservicesgroup.com
165.193.126.229 nist1-nj2.ustiming.org
Avatar of Prashant Girennavar
Prashant Girennavar
Flag of India image

Are you using Active directory?

Make sure you have set the correct registroy entry on the client PC. Check below link

http://social.technet.microsoft.com/Forums/windowsserver/en-US/c6b3754d-d3e6-41bd-ac8e-3372a1afef04/ntpserver-registry-key

w32tm /monitor will give you the exact information.

Thanks,

-Prashant Girennavar.
Avatar of Heera Bisht
Heera Bisht

Hi,

If the systems are in wokrgroup, use w32tm /unregister to unregister the ntp time source on the client system. This will remove any ntp defined settings from the registry.
and use w32tm /register to register the time source again.

IF these are domain joined system you can disable the same through group policy.
ASKER CERTIFIED SOLUTION
Avatar of Ganesh Anand
Ganesh Anand
Flag of Bahrain image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial