[chrony-users] Allowing IPv6 hosts to sync

[ Thread Index | Date Index | More chrony.tuxfamily.org/chrony-users Archives ]


Hi,

I'm running chronyd (chrony) version 1.29.1 on CentOS7 and I would
like to allow IPv6 hosts from my local network to sync with the
server.

This is the relevant part from my /etc/chrony.conf:

allow 172.16.0/24
allow 2001:444:1f0a:c9a::/64
# no deny rules present!

After saving the file and restarting chronyd I went and tried to check
if hosts are allowed:
$ chronyc -a
chrony version 1.29.1
Copyright (C) 1997-2003, 2007, 2009-2013 Richard P. Curnow and others
chrony comes with ABSOLUTELY NO WARRANTY.  This is free software, and
you are welcome to redistribute it under certain conditions.  See the
GNU General Public License version 2 for details.

200 OK
chronyc> accheck 2001:444:1f0b:c9a::12
209 Access denied
chronyc> accheck 2001:444:1f0b:c9a:20c:29ff:fe4d:357b
209 Access denied
chronyc> accheck 172.16.0.1
208 Access allowed

I also see the some "access denied" entries in the journal:
NTP packet received from unauthorised host
2001:444:1f0b:c9a:20c:29ff:fe4d:357b port 123

Any ideas what's wrong with my configuration?

Thanks,

Alex
--
Alexander Groß
http://therightstuff.de/

--
To unsubscribe email chrony-users-request@xxxxxxxxxxxxxxxxxxxx
with "unsubscribe" in the subject.
For help email chrony-users-request@xxxxxxxxxxxxxxxxxxxx
with "help" in the subject.
Trouble?  Email listmaster@xxxxxxxxxxxxxxxxxxxx.


Mail converted by MHonArc 2.6.19+ http://listengine.tuxfamily.org/