3 ms·
Some ISPs (e.g. AT&T) block outbound traffic from subscribers with source port 123, to mitigate NTP reflection attacks. Shouldn't necessarily break your NTP cl
by addingnumbers 5y ago
Some ISPs (e.g. AT&T) block outbound traffic from subscribers with source port 123, to mitigate NTP reflection attacks.
Shouldn't necessarily break your NTP client, right? The client's destination port needs to be 123 but the source port can be anything.
But many NTP clients use port 123 as both the destination and source port.
For a while I had a netfilter POSTROUTING rule that would match outbound packets with source port 123 and force translation of the source port to the 60000-65000 range, which had all my NTP clients working again.
- hda2 5y agoCan you please share the iptables rule?
- addingnumbers 5y agoiptables -t nat -I POSTROUTING -p udp -m udp --sport 123 -j MASQUERADE --to-ports 60000-61000 I don't know why I didn't specify the outbound interface but I probably should have (-o $wan_interface), anyway it did the job for a long time. The breakthrough I needed to get it to work was discovering that --to-ports option, which I'd never used or seen in the wild before facing this problem.