{"id":86141,"date":"2022-10-24T20:00:22","date_gmt":"2022-10-24T19:00:22","guid":{"rendered":"https:\/\/www.avanet.com\/kb\/configurer-sophos-firewall-comme-serveur-ntp\/"},"modified":"2022-11-08T10:44:22","modified_gmt":"2022-11-08T09:44:22","slug":"configurer-sophos-firewall-comme-serveur-ntp","status":"publish","type":"kb","link":"https:\/\/www.avanet.com\/fr\/kb\/configurer-sophos-firewall-comme-serveur-ntp\/","title":{"rendered":"Configurer Sophos Firewall comme serveur NTP"},"content":{"rendered":"\n<p>Il est vrai que le titre est erron\u00e9, car la Sophos Firewall n&rsquo;a pas de service NTP.\nIl est cependant possible de r\u00e9soudre ce probl\u00e8me en cr\u00e9ant une r\u00e8gle NAT de sorte que Sophos Firewall s&rsquo;occupe de toutes les demandes NTP et que l&rsquo;IP de la passerelle puisse \u00eatre sp\u00e9cifi\u00e9e comme serveur NTP sur le client ou le serveur. <\/p>\n\n<h2 class=\"wp-block-heading\" id=\"h-nat-ntp-regel-erstellen\">Cr\u00e9er une r\u00e8gle NAT NTP<\/h2>\n\n<p>Je commence par cr\u00e9er une r\u00e8gle NAT qui s&rsquo;occupe du protocole NTP.<\/p>\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-nat-rule-scaled.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"2560\" height=\"1259\" data-id=\"84307\" src=\"https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-nat-rule-scaled.jpg\" alt=\"\" class=\"wp-image-84307\" srcset=\"https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-nat-rule-scaled.jpg 2560w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-nat-rule-scaled-64x31.jpg 64w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-nat-rule-300x148.jpg 300w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-nat-rule-1024x504.jpg 1024w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-nat-rule-768x378.jpg 768w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-nat-rule-1536x756.jpg 1536w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-nat-rule-2048x1007.jpg 2048w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-nat-rule-600x295.jpg 600w\" sizes=\"auto, (max-width: 2560px) 100vw, 2560px\" \/><\/a><\/figure>\n<\/figure>\n\n<p>La r\u00e8gle NAT d\u00e9finit maintenant les r\u00e9seaux locaux pour lesquels Sophos Firewall doit r\u00e9pondre aux requ\u00eates NTP.<\/p>\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-2 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-nat-rule-detail-scaled.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"2560\" height=\"1849\" data-id=\"84322\" src=\"https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-nat-rule-detail-scaled.jpg\" alt=\"\" class=\"wp-image-84322\" srcset=\"https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-nat-rule-detail-scaled.jpg 2560w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-nat-rule-detail-scaled-64x46.jpg 64w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-nat-rule-detail-300x217.jpg 300w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-nat-rule-detail-1024x740.jpg 1024w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-nat-rule-detail-768x555.jpg 768w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-nat-rule-detail-1536x1110.jpg 1536w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-nat-rule-detail-2048x1479.jpg 2048w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-nat-rule-detail-600x433.jpg 600w\" sizes=\"auto, (max-width: 2560px) 100vw, 2560px\" \/><\/a><\/figure>\n<\/figure>\n\n<h3 class=\"wp-block-heading\">1. Original Source<\/h3>\n\n<p>Les r\u00e9seaux ou les adresses IP individuelles qui doivent utiliser cette r\u00e8gle NAT sont saisis ici.\nPar exemple 192.168.33.0\/24 ou ANY, si chaque demande doit \u00eatre prise en compte. <\/p>\n\n<h3 class=\"wp-block-heading\">2. Original Destination<\/h3>\n\n<p>Ici, on liste toutes les adresses IP auxquelles le Sophos Firewall doit \u00e9couter.\nPar exemple, l&rsquo;adresse de la passerelle : 192.168.12.1 ou ANY, si chaque requ\u00eate doit \u00eatre prise en compte. <\/p>\n\n<h3 class=\"wp-block-heading\">3. Original Service<\/h3>\n\n<p>Le protocole indiqu\u00e9 est <strong>NTP<\/strong>, qui est d\u00e9j\u00e0 un service pr\u00e9d\u00e9fini sur le pare-feu.<\/p>\n\n<h3 class=\"wp-block-heading\">4. Translated Source (SNAT)<\/h3>\n\n<p>Le pare-feu doit effectuer un masquage d&rsquo;IP, c&rsquo;est pourquoi nous choisissons ici <strong>MASQ<\/strong> comme valeur.<\/p>\n\n<h3 class=\"wp-block-heading\">5. Translated destination (DNAT)<\/h3>\n\n<p>Nous saisissons ici l&rsquo;adresse du serveur NTP auquel le pare-feu doit envoyer toutes les demandes de temps.\nJ&rsquo;utilise ici le FQDN <strong>time.google.com<\/strong> ou, tout aussi populaire, <strong>pool.ntp.org<\/strong>. <\/p>\n\n<h3 class=\"wp-block-heading\">Inbound Interface<\/h3>\n\n<p>En outre, il est possible de d\u00e9finir les interfaces locales afin d&rsquo;\u00eatre s\u00fbr de ne pas r\u00e9pondre aux demandes WAN.\nJe laisse ici la valeur ANY et je la r\u00e9sous ensuite via la r\u00e8gle de pare-feu. <\/p>\n\n<h2 class=\"wp-block-heading\">R\u00e8gle de pare-feu pour le service NTP<\/h2>\n\n<p>Pour que le trafic de la r\u00e8gle NAT soit autoris\u00e9, il faut une r\u00e8gle de pare-feu que l&rsquo;on cr\u00e9e maintenant.<\/p>\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-3 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-firewall-rule-scaled.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1564\" height=\"2560\" data-id=\"84327\" src=\"https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-firewall-rule-scaled.jpg\" alt=\"\" class=\"wp-image-84327\" srcset=\"https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-firewall-rule-scaled.jpg 1564w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-firewall-rule-scaled-64x105.jpg 64w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-firewall-rule-300x491.jpg 300w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-firewall-rule-183x300.jpg 183w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-firewall-rule-625x1024.jpg 625w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-firewall-rule-768x1257.jpg 768w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-firewall-rule-938x1536.jpg 938w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-firewall-rule-1251x2048.jpg 1251w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-firewall-rule-600x982.jpg 600w\" sizes=\"auto, (max-width: 1564px) 100vw, 1564px\" \/><\/a><\/figure>\n<figcaption class=\"blocks-gallery-caption\">R\u00e8gle de Sophos Firewall pour le trafic du serveur NTP<\/figcaption><\/figure>\n\n<h3 class=\"wp-block-heading\">1. Source Zones<\/h3>\n\n<p>Nous \u00e9num\u00e9rons ici toutes les zones sources, comme par exemple <strong>le LAN<\/strong>.\nCe que nous ne voulons pas voir ici, c&rsquo;est la zone <strong>WAN<\/strong>, car nous ne voulons pas y mettre \u00e0 disposition un serveur NTP pour Internet. <\/p>\n\n<h3 class=\"wp-block-heading\">2. Source Networks and Devices<\/h3>\n\n<p>Ici, nous pouvons \u00e9num\u00e9rer les m\u00eames r\u00e9seaux que dans la r\u00e8gle NAT au point 1. Source originale.\nComme je r\u00e9sous cette question par le biais de la zone, je laisse ici ANY, mais on peut bien s\u00fbr aussi d\u00e9finir les deux zones et les r\u00e9seaux source. <\/p>\n\n<h3 class=\"wp-block-heading\">3. Destination Zones<\/h3>\n\n<p>Comme notre serveur de temps se trouve sur Internet, je choisis ici la zone <strong>WAN<\/strong>.<\/p>\n\n<h3 class=\"wp-block-heading\">4. Destination Networks<\/h3>\n\n<p>Dans la r\u00e8gle NAT, j&rsquo;ai d\u00e9fini time.google.com comme serveur NTP.\nC&rsquo;est pourquoi j&rsquo;ai choisi ce FQDN, mais je pourrais le laisser sur ANY, car il est d\u00e9j\u00e0 d\u00e9fini dans la r\u00e8gle NAT.\nMais j&rsquo;aimerais voir directement dans la r\u00e8gle de pare-feu o\u00f9 va le trafic.  <\/p>\n\n<h3 class=\"wp-block-heading\">5. Services<\/h3>\n\n<p>Comme pour la r\u00e8gle NAT, nous utilisons le protocole pr\u00e9d\u00e9fini <strong>NTP<\/strong>.<\/p>\n\n<h3 class=\"wp-block-heading\">6. Detect and prevent exploits (IPS)<\/h3>\n\n<p>On a le pare-feu parce qu&rsquo;on veut aussi apporter un peu de s\u00e9curit\u00e9 au r\u00e9seau.\nC&rsquo;est pourquoi nous fournissons \u00e9galement une r\u00e8gle IPS pour le trafic NTP.\nPour cela, j&rsquo;ai simplement cr\u00e9\u00e9 une r\u00e8gle IPS avec le Smart Filter <strong>nat<\/strong>.  <\/p>\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-4 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-ips-rule-scaled.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"533\" data-id=\"84332\" src=\"https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-ips-rule-1024x533.jpg\" alt=\"\" class=\"wp-image-84332\" srcset=\"https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-ips-rule-1024x533.jpg 1024w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-ips-rule-scaled-64x33.jpg 64w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-ips-rule-300x156.jpg 300w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-ips-rule-768x400.jpg 768w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-ips-rule-1536x800.jpg 1536w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-ips-rule-2048x1067.jpg 2048w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-ips-rule-600x313.jpg 600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><figcaption>R\u00e8gle IPS NAT<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-ips-rule-add-new-1024x669.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"669\" data-id=\"84337\" src=\"https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-ips-rule-add-new-1024x669.jpg\" alt=\"\" class=\"wp-image-84337\" srcset=\"https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-ips-rule-add-new-1024x669.jpg 1024w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-ips-rule-add-new-64x42.jpg 64w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-ips-rule-add-new-300x196.jpg 300w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-ips-rule-add-new-768x502.jpg 768w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-ips-rule-add-new-1536x1003.jpg 1536w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-ips-rule-add-new-2048x1338.jpg 2048w, https:\/\/www.avanet.com\/assets\/sophos-firewall-ntp-server-ips-rule-add-new-600x392.jpg 600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><figcaption>Ajouter une nouvelle r\u00e8gle IPS pour NAT<\/figcaption><\/figure>\n<\/figure>\n\n<p>\u26a0\ufe0f La fonction IPS (Intrusion Prevention) n\u00e9cessite une licence Network Protection.<\/p>\n","protected":false},"author":5,"featured_media":0,"parent":0,"template":"","format":"standard","kb_kategorie":[407],"class_list":["post-86141","kb","type-kb","status-publish","format-standard","hentry","kb_kategorie-sophos-firewall"],"blocksy_meta":[],"acf":[],"_links":{"self":[{"href":"https:\/\/www.avanet.com\/fr\/wp-json\/wp\/v2\/kb\/86141","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.avanet.com\/fr\/wp-json\/wp\/v2\/kb"}],"about":[{"href":"https:\/\/www.avanet.com\/fr\/wp-json\/wp\/v2\/types\/kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.avanet.com\/fr\/wp-json\/wp\/v2\/users\/5"}],"wp:attachment":[{"href":"https:\/\/www.avanet.com\/fr\/wp-json\/wp\/v2\/media?parent=86141"}],"wp:term":[{"taxonomy":"kb_kategorie","embeddable":true,"href":"https:\/\/www.avanet.com\/fr\/wp-json\/wp\/v2\/kb_kategorie?post=86141"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}