<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can you restrict NTP queries and prevent NTP reflection attacks? in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/How-can-you-restrict-NTP-queries-and-prevent-NTP-reflection-attacks/m-p/21378#M5034</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;Paraphrased from my support case,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Calibri, sans-serif;"&gt;Due to the way ONTAP works, there is no ntp.conf file and so the fix will have to be an ONTAP patch. &lt;BR /&gt;&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://support.netapp.com/NOW/cgi-bin/bol?Type=Detail&amp;amp;Display=787469" style="font-weight: inherit; font-style: inherit; font-family: inherit; color: #009fda;" target="_blank"&gt;http://support.netapp.com/NOW/cgi-bin/bol?Type=Detail&amp;amp;Display=787469&lt;/A&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Calibri, sans-serif;"&gt;As a workaround either disable NTP until a fix is released, or block port 123/udp with a&amp;nbsp; firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 13 Feb 2014 15:44:53 GMT</pubDate>
    <dc:creator>spenticoff</dc:creator>
    <dc:date>2014-02-13T15:44:53Z</dc:date>
    <item>
      <title>How can you restrict NTP queries and prevent NTP reflection attacks?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/How-can-you-restrict-NTP-queries-and-prevent-NTP-reflection-attacks/m-p/21357#M5019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="http://www.symantec.com/connect/blogs/hackers-spend-christmas-break-launching-large-scale-ntp-reflection-attacks" title="http://www.symantec.com/connect/blogs/hackers-spend-christmas-break-launching-large-scale-ntp-reflection-attacks" target="_blank"&gt;http://www.symantec.com/connect/blogs/hackers-spend-christmas-break-launching-large-scale-ntp-reflection-attacks&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://isc.sans.edu/forums/diary/NTP+reflection+attack/17300" title="https://isc.sans.edu/forums/diary/NTP+reflection+attack/17300" target="_blank"&gt;https://isc.sans.edu/forums/diary/NTP+reflection+attack/17300&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our filers are being used as part of a large scale NTP reflection attack, I can find no documentation on how to turn off monlist queries.&lt;BR /&gt;Any one here have any ideas? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 05:44:07 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/How-can-you-restrict-NTP-queries-and-prevent-NTP-reflection-attacks/m-p/21357#M5019</guid>
      <dc:creator>spenticoff</dc:creator>
      <dc:date>2025-06-05T05:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: How can you restrict NTP queries and prevent NTP reflection attacks?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/How-can-you-restrict-NTP-queries-and-prevent-NTP-reflection-attacks/m-p/21362#M5022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you seeing UDP traffic with a source port of 123 leaving your network to go to the internet? If so, configure an access control list on your network egress to disallow that. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Feb 2014 19:59:20 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/How-can-you-restrict-NTP-queries-and-prevent-NTP-reflection-attacks/m-p/21362#M5022</guid>
      <dc:creator>ostiguy</dc:creator>
      <dc:date>2014-02-04T19:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: How can you restrict NTP queries and prevent NTP reflection attacks?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/How-can-you-restrict-NTP-queries-and-prevent-NTP-reflection-attacks/m-p/21369#M5026</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We don't operate the firewall, and that is a viable option, I was just looking for a netapp specific solution so I don't have to escalate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Feb 2014 21:28:34 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/How-can-you-restrict-NTP-queries-and-prevent-NTP-reflection-attacks/m-p/21369#M5026</guid>
      <dc:creator>spenticoff</dc:creator>
      <dc:date>2014-02-04T21:28:34Z</dc:date>
    </item>
    <item>
      <title>Re: How can you restrict NTP queries and prevent NTP reflection attacks?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/How-can-you-restrict-NTP-queries-and-prevent-NTP-reflection-attacks/m-p/21374#M5030</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you can create an internal NTP server (or two) it's best practice to use a few strategically placed internal NTP servers and point the rest of your infrastructure to there. You can then disable monlist on your external-facing NTP servers, it is easy in the Unix NTP server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Feb 2014 00:27:01 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/How-can-you-restrict-NTP-queries-and-prevent-NTP-reflection-attacks/m-p/21374#M5030</guid>
      <dc:creator>WSANDERSATFLEXERA</dc:creator>
      <dc:date>2014-02-13T00:27:01Z</dc:date>
    </item>
    <item>
      <title>Re: How can you restrict NTP queries and prevent NTP reflection attacks?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/How-can-you-restrict-NTP-queries-and-prevent-NTP-reflection-attacks/m-p/21378#M5034</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;Paraphrased from my support case,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Calibri, sans-serif;"&gt;Due to the way ONTAP works, there is no ntp.conf file and so the fix will have to be an ONTAP patch. &lt;BR /&gt;&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://support.netapp.com/NOW/cgi-bin/bol?Type=Detail&amp;amp;Display=787469" style="font-weight: inherit; font-style: inherit; font-family: inherit; color: #009fda;" target="_blank"&gt;http://support.netapp.com/NOW/cgi-bin/bol?Type=Detail&amp;amp;Display=787469&lt;/A&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Calibri, sans-serif;"&gt;As a workaround either disable NTP until a fix is released, or block port 123/udp with a&amp;nbsp; firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Feb 2014 15:44:53 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/How-can-you-restrict-NTP-queries-and-prevent-NTP-reflection-attacks/m-p/21378#M5034</guid>
      <dc:creator>spenticoff</dc:creator>
      <dc:date>2014-02-13T15:44:53Z</dc:date>
    </item>
    <item>
      <title>Re: How can you restrict NTP queries and prevent NTP reflection attacks?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/How-can-you-restrict-NTP-queries-and-prevent-NTP-reflection-attacks/m-p/21386#M5038</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We just received notification of Technical Support Bulletin - KB 7010104.&amp;nbsp; For cDOT the good news is there is a firewall in ONTAP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Feb 2014 21:20:58 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/How-can-you-restrict-NTP-queries-and-prevent-NTP-reflection-attacks/m-p/21386#M5038</guid>
      <dc:creator>scottgelb</dc:creator>
      <dc:date>2014-02-13T21:20:58Z</dc:date>
    </item>
    <item>
      <title>Re: How can you restrict NTP queries and prevent NTP reflection attacks?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/How-can-you-restrict-NTP-queries-and-prevent-NTP-reflection-attacks/m-p/21389#M5040</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can you link to this bulletin?&lt;/P&gt;&lt;P&gt;I'm still in 7 mode but this is good news.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Feb 2014 18:17:37 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/How-can-you-restrict-NTP-queries-and-prevent-NTP-reflection-attacks/m-p/21389#M5040</guid>
      <dc:creator>spenticoff</dc:creator>
      <dc:date>2014-02-14T18:17:37Z</dc:date>
    </item>
  </channel>
</rss>

