Hi,
I'm trying to run a tight nftables firewall rule set where outbound traffic is only allowed to specific IPs and ports. I would like to use secure NTP aka NTS for syncing the time of my cluster. The NTS-KE servers IP addresses will be regularly updated with the help of one of the scripts from this thread Firewall Alias with Domainname. However, according to the NTS spec, the NTS-KE server will tell the client the IP address of the actual NTP server, thus it can differ from the aforementioned NTS-KE servers IP address.
My question is, where can I find the NTP IPs (within chronys data) and is there already a way to get them into an IP set?
Best regards
I'm trying to run a tight nftables firewall rule set where outbound traffic is only allowed to specific IPs and ports. I would like to use secure NTP aka NTS for syncing the time of my cluster. The NTS-KE servers IP addresses will be regularly updated with the help of one of the scripts from this thread Firewall Alias with Domainname. However, according to the NTS spec, the NTS-KE server will tell the client the IP address of the actual NTP server, thus it can differ from the aforementioned NTS-KE servers IP address.
My question is, where can I find the NTP IPs (within chronys data) and is there already a way to get them into an IP set?
Best regards