Skip to main content
Question

NTP set to loopback?

  • June 14, 2018
  • 5 replies
  • 12 views

ImAMacGuy
Forum|alt.badge.img+23

I'm going through our PCI audit results and one of the things I need to look into is setting up the NTP being configured to loopback. This strikes me as being bad for AD enabled machines and the time drift, or am I not understanding what setting it to loopback actually is? What are the impacts of doing this?

5 replies

davidacland
Forum|alt.badge.img+18
  • Valued Contributor
  • June 14, 2018

I haven't heard of that being used. It's technical possible, but wouldn't keep accurate time.

We always set them to use the AD domain.


Forum|alt.badge.img+1
  • New Contributor
  • June 15, 2018

To implement this, the code below may help. Kudos to @franton

NTP loopback

I am not sure on impact of doing this.


Forum|alt.badge.img+23
  • Esteemed Contributor
  • June 15, 2018

Hello.

I implemented this as per the CIS guide but frankly I think it's pointless. I always point corporate devices to the internal NTP services, whether they be the stratum 1/2 servers or to the AD domain controller(s) IF they're running NTP services. (learned the hard way that Windows Time Services != NTP ... too bad the people I worked for never did).


ImAMacGuy
Forum|alt.badge.img+23
  • Author
  • Esteemed Contributor
  • June 18, 2018

we have our internal NTP servers & apple's time servers (for DEP reasons). Not sure if there was anything that may not work because of setting to loopback. I thought it was kind of pointless too.


sdagley
Forum|alt.badge.img+25
  • Jamf Heroes
  • June 18, 2018

It doesn't address the CIS guide, but to appease the firewall admins at a previous org that refused to open an NTP port to time.aople.com I had the DNS folks redirect time.apple.com to an internal NTP server. While it'd have been easy enough to edit the hosts file on a Mac this solution also addressed the needs of iOS devices (which I think still have no method to re-direct NTP queries)