1-13
Configuring NTP Authentication
The NTP authentication feature should be enabled for a system running NTP in a network where there
is a high security demand. This feature enhances the network security by means of client-server key
authentication, which prohibits a client from synchronizing with a device that has failed authentication.
Configuration Prerequisites
The configuration of NTP authentication involves configuration tasks to be implemented on the client
and on the server.
When configuring the NTP authentication feature, pay attention to the following principles:
z
For all synchronization modes, when you enable the NTP authentication feature, you should
configure an authentication key and specify it as a trusted key. Namely, the
ntp-service
authentication enable
command must work together with the
ntp-service authentication-keyid
command and the
ntp-service reliable authentication-keyid
command. Otherwise, the NTP
authentication function cannot be normally enabled.
z
For the client/server mode or symmetric mode, you need to associate the specified authentication
key on the client (symmetric-active peer if in the symmetric peer mode) with the corresponding
NTP server (symmetric-passive peer if in the symmetric peer mode). Otherwise, the NTP
authentication feature cannot be normally enabled.
z
For the broadcast server mode or multicast server mode, you need to associate the specified
authentication key on the broadcast server or multicast server with the corresponding NTP server.
Otherwise, the NTP authentication feature cannot be normally enabled.
z
For the client/server mode, if the NTP authentication feature has not been enabled for the client,
the client can synchronize with the server regardless of whether the NTP authentication feature
has been enabled for the server or not. If the NTP authentication is enabled on a client, the client
can be synchronized only to a server that can provide a trusted authentication key.
z
For all synchronization modes, the server side and the client side must be consistently configured.
Configuration Procedure
Configuring NTP authentication for a client
Follow these steps to configure NTP authentication for a client:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enable NTP authentication
ntp-service authentication
enable
Required
Disabled by default
Configure an NTP
authentication key
ntp-service
authentication-keyid
keyid
authentication-mode
md5
value
Required
No NTP authentication key by
default
Configure the key as a trusted
key
ntp-service reliable
authentication-keyid keyid
Required
No authentication key is
configured to be trusted by
default.
Summary of Contents for S5500-SI Series
Page 161: ...3 10 GigabitEthernet1 0 1 2 MANUAL...
Page 220: ...1 7 Clearing ARP entries from the ARP table may cause communication failures...
Page 331: ...1 7 1 1 ms 1 ms 1 ms 1 1 6 1 2 1 ms 1 ms 1 ms 1 1 4 1 3 1 ms 1 ms 1 ms 1 1 2 2 Trace complete...
Page 493: ...2 8...
Page 1111: ...1 10 Installing patches Installation completed and patches will continue to run after reboot...