driftfile /var/lib/ntp/ntp.drift leapfile /usr/share/zoneinfo/leap-seconds.list # Redundant upstream time sources: pfv-netinfra-01/02 (Technitium/Pi-hole hosts # also serving NTP). IPs are used (not hostnames) because the knel.net name for # these hosts resolves to a Tailscale CGNAT address, not the LAN address, and # because NTP must come up before DNS is available. iburst speeds initial sync. server 192.168.3.252 iburst server 192.168.3.253 iburst # Hardened client: sync from the configured servers but never serve time to # anyone else. Note: `interface listen 127.0.0.1` must NOT be used here — it # binds ntpd to loopback, making outbound queries carry a 127.0.0.1 source # address that upstream servers cannot reply to (symptoms: peers stuck in # .INIT. with reach 0). Use restrict rules to control access instead. restrict default ignore restrict 127.0.0.1 restrict ::1 restrict 192.168.3.252 nomodify notrap nopeer restrict 192.168.3.253 nomodify notrap nopeer