Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Connect w/ Internet time-source through PIX 1

Status
Not open for further replies.

DaveNeubauer

IS-IT--Management
Jul 29, 2002
33
DE
I'm having trouble connecting to a NTP server on the Internet. My NT PDC is acting as the local time-source for other LAN equipment. The PDC connects to a PIX-515, and the PIX connects to a Cisco router on it's way to an external NTP server. My current config uses access-list commands, but should I consider conduits instead?

Would someone be able to provide the syntax for me? I can't seem to get the access-list command to work properly. Or perhaps some troubleshooting advice would be helpful.

TIA, DAve
 
HI.

What is your pix OS version?
Do you have PDM on it?

The following links can help you:

The pixcript utility can also help you with the syntax of conduit versus access-list:

Do not mix conduit and access-list together as such configuration will be very problematic to manage.

I guess that this sample will do the trick:
static REGISTEREDIP PRIVATEIP
access-list fromoutside permit udp host TIMESERVER host REGISTEREDIP eq 123
access-list fromoutside permit tcp host TIMESERVER host REGISTEREDIP eq 123
access-group fromoutside in interface outside

You can and should use syslog messages for troubleshooting.

Bye
Yizhar Hurwitz
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top