CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point SecurePlatform (SPLAT)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-05-05
Senior Member
 
Join Date: 2007-06-05
Location: Canada
Posts: 203
Rep Power: 2
hotice_ has an average reputation (10+)
Default NTP Server feature in SPLAT - feat request?

Does anyone know if Checkpoint has any intention of embedding NTP Server as (not clients) as a feature within Secure Platform in the near future?

I've got a lot of client requests so far on this and have already forwarded this to our SE as a feature request...
Reply With Quote
  #2 (permalink)  
Old 2008-05-10
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 586
Rep Power: 10
BarryStiefel has disabled reputation
Default Re: NTP Server feature in SPLAT - feat request?

Quote:
Originally Posted by hotice_ View Post
Does anyone know if Checkpoint has any intention of embedding NTP Server as (not clients) as a feature within Secure Platform in the near future?

I've got a lot of client requests so far on this and have already forwarded this to our SE as a feature request...
This makes me nervous. I don't like anyone connecting to my Security Gateway for any reason.
__________________
Barry J. Stiefel ("Stee-ful")
CCSA/CCSE/CCSE+/CCSI
President, CPUG
Reply With Quote
  #3 (permalink)  
Old 2008-05-10
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,681
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: NTP Server feature in SPLAT - feat request?

It would make sense on the SmartCenter, but not on a gateway.
Reply With Quote
  #4 (permalink)  
Old 2008-05-10
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 586
Rep Power: 10
BarryStiefel has disabled reputation
Default Re: NTP Server feature in SPLAT - feat request?

Quote:
Originally Posted by chillyjim View Post
It would make sense on the SmartCenter, but not on a gateway.
Shouldn't this be considered one of the administrative services that goes on the same server as DNS, DHCP, or
Windows AD Domain Controller? I really like my Security Gateways to be stripped down and hardened and invisible.
__________________
Barry J. Stiefel ("Stee-ful")
CCSA/CCSE/CCSE+/CCSI
President, CPUG
Reply With Quote
  #5 (permalink)  
Old 2008-05-10
Senior Member
 
Join Date: 2007-07-16
Posts: 693
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: NTP Server feature in SPLAT - feat request?

I brought this up as a feature request a long time ago (actually I suggested that they include time sync as part of the SIC registration process, due to the issues with time registration and the validity of certs...). At the time I was told that it would not happen, because it opened a number of technical issues around the more general issues of clock and time syncronisation that CP weren't willing to invest time and effort into.

I still think this is a bit of a mistake on CP's part. Considering the importance of accurate timestamping for the validity of logs as well as the SIC issues that can potentially occur because of time issues, I'd support CP taking the time management function in as part of the product. It seems logical to me to use a SmartCenter/Provider-1 server as a time server for gateways, and not have them rely of a third-party time system which itself would need to be adequately protected.
Reply With Quote
  #6 (permalink)  
Old 2008-05-10
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 586
Rep Power: 10
BarryStiefel has disabled reputation
Default Re: NTP Server feature in SPLAT - feat request?

Quote:
Originally Posted by Thorpuse View Post
I brought this up as a feature request a long time ago (actually I suggested that they include time sync as part of the SIC registration process, due to the issues with time registration and the validity of certs...). At the time I was told that it would not happen, because it opened a number of technical issues around the more general issues of clock and time syncronisation that CP weren't willing to invest time and effort into.

I still think this is a bit of a mistake on CP's part. Considering the importance of accurate timestamping for the validity of logs as well as the SIC issues that can potentially occur because of time issues, I'd support CP taking the time management function in as part of the product. It seems logical to me to use a SmartCenter/Provider-1 server as a time server for gateways, and not have them rely of a third-party time system which itself would need to be adequately protected.
Using SIC to synchronize time from the SCS out to all the other machines might be rather nice. You'd have to think about time zone issues, though.
__________________
Barry J. Stiefel ("Stee-ful")
CCSA/CCSE/CCSE+/CCSI
President, CPUG
Reply With Quote
  #7 (permalink)  
Old 2008-05-11
Senior Member
 
Join Date: 2007-07-16
Posts: 693
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: NTP Server feature in SPLAT - feat request?

Quote:
Originally Posted by BarryStiefel View Post
Using SIC to synchronize time from the SCS out to all the other machines might be rather nice. You'd have to think about time zone issues, though.
Among other things.... different OSes manage time in different ways, drift and latency issues if you're going to time-sync properly, administrative/OS rights to change time, daylight savings...

Still think it's worth arguing... I've started a policy on most of the firewalls I deal with to set them all to UTC - just got too tired of all the daylight savings changes!
Reply With Quote
  #8 (permalink)  
Old 2008-05-11
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 586
Rep Power: 10
BarryStiefel has disabled reputation
Default Re: NTP Server feature in SPLAT - feat request?

Quote:
Originally Posted by Thorpuse View Post
Among other things.... different OSes manage time in different ways, drift and latency issues if you're going to time-sync properly, administrative/OS rights to change time, daylight savings...

Still think it's worth arguing... I've started a policy on most of the firewalls I deal with to set them all to UTC - just got too tired of all the daylight savings changes!
I'm with you on the UTC idea, especially if you've got equipment in different time zones. Sometimes if I'm travelling and blasting through a lot of different time zones, I'll even set my watch to UTC and just remember how many delta hours there are wherever it is that I am.

And now that even the dates that DST comes in to play keep changing, it gets much worse. I still use Windows 2000 machines that don't change over on the correct dates. Grrr.
__________________
Barry J. Stiefel ("Stee-ful")
CCSA/CCSE/CCSE+/CCSI
President, CPUG
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 09:24.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0