HOME LITERATURE MarketNotes
ZoneRanger: Secure NTP Proxy Print

The Network Time Protocol (NTP) is an older, but still very useful, Internet protocol designed to allow network devices and servers to synchronize their clocks with one or more centralized time servers, across a variable-latency network. In applications where time synchronization across devices is important, the ability to administer time across a large number of devices from a small number of centralized time servers using NTP is a significant advantage.

The common industry practice where networks are partitioned into security zones using conventional firewalls creates a problem for NTP, requiring network administrators to choose between two equally unacceptable alternatives: prevent NTP traffic from passing through the firewall, effectively isolating the devices beyond from the primary time servers, or allow NTP traffic to pass through the firewall, accepting the associated security risks.

ZoneRanger resolves this dilemma, acting as an application-layer proxy firewall for NTP traffic, enabling network devices and servers to effectively reach back through the firewalls to the centralized time servers, while mitigating the associated security risks through careful inspection and filtering of all NTP traffic.  

ZoneRanger’s NTP proxy service can be configured to operate in either of two modes:

  • The ZoneRanger can obtain its time from a centralized NTP server, and can act as a secondary time server, responding autonomously to NTP requests from client devices.
  • The ZoneRanger can act as straight NTP protocol proxy, inspecting NTP requests received from client devices, relaying valid requests onto a centralized timer server, and relaying server responses back to the requesting clients.
NTP diagram
NTP diagram

NTP is part of a growing suite of management protocols supported by ZoneRanger. Other supported protocols include:

 

How does ZoneRanger fit into your network?

What others are saying...

"Tavve has developed the ZoneRanger product, in order to enable companies to leverage their centralized management infrastructure across firewall-partitioned networks, while mitigating risks associated with management protocols."
Tavve: ZoneRanger 
Subraya Mallya
PrudentCloud.com


"Without a more secure approach to managing the protocols and tools that manage the network - including the 'trusted' internal network - enterprises may be exposing themselves to more risk than they realize."

Scott Crawford, CISSP, ISSAP, ISSMP
Senior Analyst, Enterprise Management Associates

"ZoneRanger effectively extends the reach of management applications to devices located beyond firewalls, eliminating the need for complicated firewall configurations, extensive agent deployments, or expensive application replication. ZoneRanger also provides security, acting as an application layer proxy firewall, inspecting and validating the traffic relayed between applications and devices.
Jim Doble, CISSP
CTO, Tavve