118
Step
Command
Remarks
2.
Specify an NTP server for
the device.
•
For IPv4:
sntp unicast-server
{
server-name
|
ip-address
}
[
vpn-instance
vpn-instance-name
]
[
authentication-keyid
keyid
|
source
interface-type
interface-number
|
version
number
] *
•
For IPv6:
sntp ipv6 unicast-server
{
server-name
|
ipv6-address
}
[
vpn-instance
vpn-instance-name
]
[
authentication-keyid
keyid
|
source
interface-type
interface-number
] *
By default, no NTP server is
specified for the device.
Repeat this step to specify
multiple NTP servers.
To use authentication, you must
specify the
authentication-keyid
keyid
option.
To use an NTP server as the time source, make sure its clock has been synchronized. If the stratum
level of the NTP server is greater than or equal to that of the client, the client does not synchronize
with the NTP server.
Configuring SNTP authentication
SNTP authentication ensures that an SNTP client is synchronized only to an authenticated
trustworthy NTP server.
Follow these guidelines when you configure SNTP authentication:
•
Enable authentication on both the NTP server and the SNTP client.
•
Configure the SNTP client to use the same authentication key ID and key value as the NTP
server, and specify the key as a trusted key on both the NTP server and the SNTP client. For
information about configuring NTP authentication on an NTP server, see "
."
•
Associate the specified key with an NTP server on the SNTP client.
With authentication disabled, the SNTP client can synchronize with the NTP server regardless of
whether the NTP server is enabled with authentication.
To configure SNTP authentication on the SNTP client:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable SNTP authentication.
sntp authentication enable
By default, SNTP authentication is
disabled.
3.
Configure an SNTP
authentication key.
sntp
authentication-keyid
keyid
authentication-mode
{
hmac-sha-1
|
hmac-sha-256
|
hmac-sha-384
|
hmac-sha-512
|
md5
} {
cipher
|
simple
}
string
[
acl
ipv4-acl-number
|
ipv6
acl
ipv6-acl-number
] *
By default, no SNTP
authentication key exists.
4.
Specify the key as a trusted
key.
sntp reliable
authentication-keyid keyid
By default, no trusted key is
specified.
Summary of Contents for FlexNetwork 10500 SERIES
Page 224: ...213 ...
Page 311: ...300 Now the system can record log information to the specified file ...