diff options
| author | Ruben Herold <ruben@puettmann.net> | 2026-08-03 23:14:08 +0200 |
|---|---|---|
| committer | Ruben Herold <ruben@puettmann.net> | 2026-08-03 23:14:08 +0200 |
| commit | 8381edc12a116eee3a524ee5d060c057cb039f47 (patch) | |
| tree | 8bf28a014b8dd8cdc67d1f739120a91877572eec /src/migration-scripts | |
| parent | dd2673bf9ad36ea7ecb6998b71f318516b95e8d8 (diff) | |
| download | vyos-1x-8381edc12a116eee3a524ee5d060c057cb039f47.tar.gz vyos-1x-8381edc12a116eee3a524ee5d060c057cb039f47.zip | |
ntp: T9159: add source-address option for client requests
chrony (the daemon backing VyOS' NTP service) has no way to pin the
local address used for outgoing client requests to upstream servers.
"interface"/"listen-address" only configure the server/listening role
(binddevice/bindaddress); nothing controls the source address chosen
for packets chronyd itself originates.
On a router with more than one usable egress path to a given NTP
server (e.g. multiple transit/peering sessions), the kernel's default
source-address selection depends on whichever route wins at query
time. If that route happens to egress through an interface whose own
address is not globally reachable (a private peering-fabric segment,
for example), the request goes out with an address the reply can
never route back to - an intermittent, path-dependent failure with no
existing workaround at the NTP layer. BGP and friends already solve
the equivalent problem via "update-source" bound to the loopback;
NTP had no analogous option.
Add "service ntp source-address <address>", reusing the existing
source-address-ipv4-ipv6-multi include (same pattern already used for
e.g. RADIUS servers), and render it as chrony's "bindacqaddress"
directive - the client-side counterpart to "bindaddress" that chrony
already supports natively.
Diffstat (limited to 'src/migration-scripts')
0 files changed, 0 insertions, 0 deletions
