The ntp.conf hardening used `interface ignore wildcard` + `interface listen 127.0.0.1`, which binds ntpd to loopback only. Outbound NTP queries to the upstream servers then carried a 127.0.0.1 source address that the servers cannot reply to, so the daemon's peers stayed stuck in .INIT. with reach 0 — even though the servers are reachable (verified: ntpdate -q succeeds, ntpd does not). Replace the interface-based restriction with restrict-based hardening: `restrict default ignore` blocks unsolicited queries from any host (so the box never serves time to others), while explicit allow rules for the two upstream servers and localhost let the client sync normally. 🤖 Generated with [Crush](https://github.com/charmassociates/crush) Assisted-by: GLM-5 via Crush <crush@charm.land>
22 lines
979 B
Plaintext
22 lines
979 B
Plaintext
driftfile /var/lib/ntp/ntp.drift
|
|
leapfile /usr/share/zoneinfo/leap-seconds.list
|
|
|
|
# Redundant upstream time sources: pfv-netinfra-01/02 (Technitium/Pi-hole hosts
|
|
# also serving NTP). IPs are used (not hostnames) because the knel.net name for
|
|
# these hosts resolves to a Tailscale CGNAT address, not the LAN address, and
|
|
# because NTP must come up before DNS is available. iburst speeds initial sync.
|
|
server 192.168.3.252 iburst
|
|
server 192.168.3.253 iburst
|
|
|
|
# Hardened client: sync from the configured servers but never serve time to
|
|
# anyone else. Note: `interface listen 127.0.0.1` must NOT be used here — it
|
|
# binds ntpd to loopback, making outbound queries carry a 127.0.0.1 source
|
|
# address that upstream servers cannot reply to (symptoms: peers stuck in
|
|
# .INIT. with reach 0). Use restrict rules to control access instead.
|
|
restrict default ignore
|
|
restrict 127.0.0.1
|
|
restrict ::1
|
|
restrict 192.168.3.252 nomodify notrap nopeer
|
|
restrict 192.168.3.253 nomodify notrap nopeer
|
|
|