Hi, Our Web Servers are placed in DMZ and when i try to update time synchronization then it shows me error. Seems something is getting blocked. Has NTP required to be add in the default inspection. Please suggest. Thanks.
I believe that there is not enough information here for us to really understand and provide answers about your issue. What device is providing the DMZ functionality (PIX, ASA, router, something else)? What access policies are in place for the DMZ? How are your web servers configured to get time? By default Windows servers run the Windows time service which implements a simplified version of NTP.
With normal access policies on a DMZ if the Windows server sends a request for time to some appropriate time source on the outside, since the request originated from inside the DMZ then responses should be allowed. If the time information is included in transmission originated from devices on the outside then you would need to configure access rules to permit this. If the request for time is sent from the server in the DMZ to some appropriate time source on the inside network then you would need to configure access rules to permit this traffic.
If you can clarify these aspects then perhaps we can provide better answers.
We are using ASA 5505. Application Servers are placed on DMZ and DB Servers are on Inside. The all App Server are mapped with Static Public IP and time is getting synchronized in App Server but not in DB Servers. We can access internet from DB and App Servers. Please Advice and let me know if you want anything else. Thanks
BenefitsDocumentationPrerequisiteImage Download LinksLimitationsSupported PlatformsLicense RequirementsTopologyStep-By-Step ConfigurationConfigure Virtual ServiceActivate the virtual service and configure guest IPsConfiguring UTD (Service Plane)Configurin...
Login to the FXOS chassis manager.
Direct your browser to https://hostname/, and log-in using the user-name and password.
Go to Help > About and check the current version:
Check the current version availa...
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...