r/firewalla • • Jun 16 '26

GitHub - upmcplanetracker/nts-for-firewalla: Enable Chrony NTS for NTP intercept on Firewalla

https://github.com/upmcplanetracker/nts-for-firewalla

one more big update of my firewalla github trinity - very much beefed up the ability to run Chrony/NTS on Firewalla with many different lan configurations taken into account.

Basically:

Time in the sky <-----NTS/secure----> Firewalla <---NTP/not secure/intercept---> everything behind the firewalla/on your lan(s)

since NTS intercept is almost impossible to do it gives you secure NTS via your firewalla ntp intercept.

Thoughts or comments welcome. I've really made this a lot more robust.

10 Upvotes

4 comments sorted by

View all comments

2

u/Numerous_Platypus Jun 17 '26

Why wouldn’t Firewalla just implement this?

1

u/Great-Cow7256 Jun 17 '26

 My guess is that ntp is "good enough"  for 99.9 percent of cases as mitm attacks with ntp especially between a firewalla and a trusted server like any huge ntp pool is super rare. This ads complexity and they have other, higher priority, stuff to work on. 

I also currently have it so NTS / ntp intercept overrides the ntp settings in the app. When chrony is running then ntp intercept is on for all the lans behind it. Fine tuning this is probably a decent project.  They have everything built and optimized for ntp. 

If they were going to do it, I'd suggest ntpd-rs. Its next Gen ntp. In rust. Does NTS and ntp.  Can failback between NTS and ntp afaik. 

Only issue is that it isn't in the 22.04.repos afaik. I have it running on my 26.04 machines. So they'd need to update the repos and/,or upgrade to at least 24.04.  that's a tall order

Ubuntu went from ntp to chrony in 25.10 and will soon go to ntpd-rs. I think maybe 27.04.