How to receive feedback on a pending vendor zone request

Bas is correct, a vendor can deploy their own DNS/NTP servers. Many do (Apple, Microsoft, Google, etc.). A case can be made for vendor pools though. My example uses Fortinet’s FortiGate firewall.

FortiGate documentation says to use the NTP Pool. No problems for several years. In December 2019 Fortinet/FortiGate released broken software that sent high rate NTP bursts (sometimes exceeding 30,000 requests/sec) to NTP Pool servers world wide. I’ve been chasing this problem for over two years, Fortinet/FortiGate has not been helpful. 2.5 years later the bursts are still seen.

If FortiGate instead used a vendor pool (e.g., 0.fortigate.pool.ntp.org), one of the NTP Pool administrators could have redirected the bursts away from the NTP Pool) using DNS when the problem occurred.

There is a long history of abusive NTP clients. Vendors should never hard code an NTP Pool DNS name into their products unless a vendor pool is used.

3 Likes