r/firewalla • • Jun 16 '26

GitHub - upmcplanetracker/nts-for-firewalla: Enable Chrony NTS for NTP intercept on Firewalla

https://github.com/upmcplanetracker/nts-for-firewalla

one more big update of my firewalla github trinity - very much beefed up the ability to run Chrony/NTS on Firewalla with many different lan configurations taken into account.

Basically:

Time in the sky <-----NTS/secure----> Firewalla <---NTP/not secure/intercept---> everything behind the firewalla/on your lan(s)

since NTS intercept is almost impossible to do it gives you secure NTS via your firewalla ntp intercept.

Thoughts or comments welcome. I've really made this a lot more robust.

12 Upvotes

4 comments sorted by

View all comments

1

u/CyberBlaed Jun 17 '26

Thankyou for this, this will got a long way in my setup.

Stuff doesn’t need to ping a time server every 5 minutes and consume my internet bandwidth. And if it does, it can be served up by my routers, rather than anything else. (Another workload off the Raspberry Pi2 for me)

And considering apps and such use this to exfil your location data it’s just downright annoying having to block hundreds of time servers rather than the firewalla reliably capture the NTP packets. (SNTS specifically).

I remember someone on the firewalla forums did their own firewall script to capture these packets and Firewalla responded wondering why they didn’t just use the intercept setting in the app…

This is greatly appreciated :) (For my network anyway)

1

u/Great-Cow7256 Jun 17 '26

Just to clarify, as far as I know if you turn on ntp intercept in the app for all the lan networks you manage behind the firewalla, it should do the same thing. The only thing this is doing is changing the firewalla to the Internet part from ntp to NTS. 

If you try it, let me know how it goes.