Firewall Wizards mailing list archives

Re: Acqusition of time


From: Volker Tanger <volker.tanger () discon de>
Date: Wed, 29 Jan 2003 18:33:59 +0100

Greetings!

Brian Monkman wrote:

We are talking about a firewall farm. [...] central logging server.
[...]
In your opinion - should we have a battery backed-up clock on these firewalls or is the network time source sufficient?

Do both - the battery back-up for having an approximately accurate time in case of rebooting during problems with the external time source. Network problems are more probable than attacks against radio or GPS clocks here.

But for a real sync between the servers you need them to synchronize onto the same source - be it via network (same, preferrably internal NTP server) or via the same external source (radio clock or GPS clock).

Bye

Volker Tanger
IT-Security Consulting

--
discon gmbh
WrangelstraƟe 100
D-10997 Berlin

fon    +49 30 6104-3307
fax    +49 30 6104-3461

volker.tanger () discon de
http://www.discon.de/


_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: