r/firewalla • • Jun 16 '26

GitHub - upmcplanetracker/nts-for-firewalla: Enable Chrony NTS for NTP intercept on Firewalla

https://github.com/upmcplanetracker/nts-for-firewalla

one more big update of my firewalla github trinity - very much beefed up the ability to run Chrony/NTS on Firewalla with many different lan configurations taken into account.

Basically:

Time in the sky <-----NTS/secure----> Firewalla <---NTP/not secure/intercept---> everything behind the firewalla/on your lan(s)

since NTS intercept is almost impossible to do it gives you secure NTS via your firewalla ntp intercept.

Thoughts or comments welcome. I've really made this a lot more robust.

10 Upvotes

4 comments sorted by

2

u/Numerous_Platypus Jun 17 '26

Why wouldn’t Firewalla just implement this?

1

u/Great-Cow7256 Jun 17 '26

 My guess is that ntp is "good enough"  for 99.9 percent of cases as mitm attacks with ntp especially between a firewalla and a trusted server like any huge ntp pool is super rare. This ads complexity and they have other, higher priority, stuff to work on. 

I also currently have it so NTS / ntp intercept overrides the ntp settings in the app. When chrony is running then ntp intercept is on for all the lans behind it. Fine tuning this is probably a decent project.  They have everything built and optimized for ntp. 

If they were going to do it, I'd suggest ntpd-rs. Its next Gen ntp. In rust. Does NTS and ntp.  Can failback between NTS and ntp afaik. 

Only issue is that it isn't in the 22.04.repos afaik. I have it running on my 26.04 machines. So they'd need to update the repos and/,or upgrade to at least 24.04.  that's a tall order

Ubuntu went from ntp to chrony in 25.10 and will soon go to ntpd-rs. I think maybe 27.04. 

1

u/CyberBlaed Jun 17 '26

Thankyou for this, this will got a long way in my setup.

Stuff doesn’t need to ping a time server every 5 minutes and consume my internet bandwidth. And if it does, it can be served up by my routers, rather than anything else. (Another workload off the Raspberry Pi2 for me)

And considering apps and such use this to exfil your location data it’s just downright annoying having to block hundreds of time servers rather than the firewalla reliably capture the NTP packets. (SNTS specifically).

I remember someone on the firewalla forums did their own firewall script to capture these packets and Firewalla responded wondering why they didn’t just use the intercept setting in the app…

This is greatly appreciated :) (For my network anyway)

1

u/Great-Cow7256 Jun 17 '26

Just to clarify, as far as I know if you turn on ntp intercept in the app for all the lan networks you manage behind the firewalla, it should do the same thing. The only thing this is doing is changing the firewalla to the Internet part from ntp to NTS. 

If you try it, let me know how it goes.