<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic use Palo as an NTP device in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/use-palo-as-an-ntp-device/m-p/46872#M34450</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; We have 2 * 2050's running 4.0.7 here and I was wondering if I could use these devices as NTP servers for other devices to sync against?&amp;nbsp; I've looked through the gui but can't see any way to do it so far.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 19 Apr 2012 09:00:46 GMT</pubDate>
    <dc:creator>chrismckean</dc:creator>
    <dc:date>2012-04-19T09:00:46Z</dc:date>
    <item>
      <title>use Palo as an NTP device</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/use-palo-as-an-ntp-device/m-p/46872#M34450</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; We have 2 * 2050's running 4.0.7 here and I was wondering if I could use these devices as NTP servers for other devices to sync against?&amp;nbsp; I've looked through the gui but can't see any way to do it so far.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Apr 2012 09:00:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/use-palo-as-an-ntp-device/m-p/46872#M34450</guid>
      <dc:creator>chrismckean</dc:creator>
      <dc:date>2012-04-19T09:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: use Palo as an NTP device</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/use-palo-as-an-ntp-device/m-p/46873#M34451</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not that im aware of.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However I think you could setup a DNAT rule to forward the NTP request made against some ip thats routed through the PA device (or ip which is already been used by the PA) into some NTP server of your choice.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example if you only use RFC1918 addresses in your core you could address the ip of the PA device and with DNAT similar to:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;srczone: inner&lt;/P&gt;&lt;P&gt;dstzone: inner&lt;/P&gt;&lt;P&gt;srcip: innerrange/cidr&lt;/P&gt;&lt;P&gt;dstip: PA_ip&lt;/P&gt;&lt;P&gt;service: udp123&lt;/P&gt;&lt;P&gt;translated dstzone: outer&lt;/P&gt;&lt;P&gt;translated dstip: NTP_ip_on_outer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;along with a security rule that allows inner to reach outer for particular service like udp123 (and ip) and appid=ntp.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Apr 2012 09:53:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/use-palo-as-an-ntp-device/m-p/46873#M34451</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-04-19T09:53:13Z</dc:date>
    </item>
    <item>
      <title>Re: use Palo as an NTP device</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/use-palo-as-an-ntp-device/m-p/46874#M34452</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the suggestion Mikand.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Apr 2012 13:17:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/use-palo-as-an-ntp-device/m-p/46874#M34452</guid>
      <dc:creator>chrismckean</dc:creator>
      <dc:date>2012-04-20T13:17:56Z</dc:date>
    </item>
  </channel>
</rss>

