do not i repeat...do not allow inbound ntp with a source port above the root ports. #################################### # delbert.hudson@xxxxxxxxxxxxxxxxx # # 61cs/scbn, 3-0182 # #################################### -----Original Message----- From: netfilter-admin@xxxxxxxxxxxxxxxxxxx [mailto:netfilter-admin@xxxxxxxxxxxxxxxxxxx]On Behalf Of Gavin Hamill Sent: Friday, July 02, 2004 4:07 AM To: netfilter@xxxxxxxxxxxxxxxxxxx Subject: Re: NTP On Friday 02 July 2004 11:57, Steve Comfort wrote: > Hi all, > > Could someone tell me what rules I need in order to enable NTP? Simply allow incoming UDP on port 123. The 'normal' way is for both the source and destination ports to be 123, but it is common (esp. with debugging) for the source port to be >1024. Cheers, Gavin.