Page 12-4
When planning your network, it is helpful to use the following general rules:
• It is usually not a good idea to synchronize a local time server with a peer (in other words,
a server at the same stratum), unless the latter is receiving time updates from a source that
has a lower stratum then from where the former is receiving time updates. This minimizes
common points of failure.
• Peer associations should only be configured between servers at the same stratum level.
Higher Strata should configure lower Strata, not the reverse.
• It is inadvisable to configure time servers in a domain to a single time source. Doing so
invites common points of failure.
NTP and Authentication
NTP
is designed to use either
DES
or MD5 encryption authentication to prevent outside influ-
ence upon
NTP
timestamp information. This is done by using a key file. The key file is loaded
into the switch memory, and consists of a text file that lists key identifiers that correspond to
particular
NTP
entities.
If authentication is enabled on an
NTP
switch, any
NTP
message sent to the switch must
contain the correct key
ID
in the message packet to use in decryption. Likewise, any message
sent from the authentication enabled switch will not be readable unless the receiving
NTP
entity possesses the correct key
ID
.
Key files are created by a system administrator independent of the
NTP
protocol, and then
placed in the switch memory. An example of a key file is show below:
1
N
29233e0461ecd6ae
# des key in NTP format
2
M
RIrop8KPPvQvYotM
# md5 key as an ASCII random string
14
M
sundial
# md5 key as an ASCII string
15
A
sundial
# des key as an ASCII string
In a key file, the first token is the key number
ID
, the second is the key format, and the third
is the key itself. (The text following a “#” is not counted as part of the key, and is used
merely for description.) There are 4 key formats:
N
Indicates a
DES
key written as a hex number, in
NTP
standard
format with the high order bit of each octet being the odd
parity bit.
M
Indicates an MD5 key written as a 1 to 31 character
ASCII
string
with each character standing for a key octet.
A
Indicates a
DES
key written as a 1 to 8 character string in 7-bit
ASCII
format, where each character stands for a key octet string.
S
Indicates a
DES
key written as a hex number in the
DES
stan-
dard format, with the low order bit of each octet being the odd
parity bit.
For information on activating authentication, specifying the location of a key file, and config-
uring key
ID
s for switches, see the following sections:
•
Configuring an NTP Client
on page 12-6
•
Configuring a New Peer Association
on page 12-12
•
Configuring a New Server
on page 12-13
•
Configuring a Broadcast Time Service
on page 12-13
Содержание Omni Switch/Router
Страница 1: ...Part No 060166 10 Rev C March 2005 Omni Switch Router User Manual Release 4 5 www alcatel com ...
Страница 4: ...page iv ...
Страница 110: ...WAN Modules Page 3 40 ...
Страница 156: ...UI Table Filtering Using Search and Filter Commands Page 4 46 ...
Страница 164: ...Using ZMODEM Page 5 8 ...
Страница 186: ...Displaying and Setting the Swap State Page 6 22 ...
Страница 202: ...Creating a New File System Page 7 16 ...
Страница 270: ...Displaying Secure Access Entries in the MPM Log Page 10 14 ...
Страница 430: ...OmniChannel Page 15 16 ...
Страница 496: ...Configuring Source Route to Transparent Bridging Page 17 48 ...
Страница 542: ...Dissimilar LAN Switching Capabilities Page 18 46 ...
Страница 646: ...Application Example DHCP Policies Page 20 30 ...
Страница 660: ...GMAP Page 21 14 ...
Страница 710: ...Viewing the Virtual Interface of Multicast VLANs Page 23 16 ...
Страница 722: ...Application Example 5 Page 24 12 ...
Страница 788: ...Viewing UDP Relay Statistics Page 26 24 ...
Страница 872: ...The WAN Port Software Menu Page 28 46 ...
Страница 960: ...Deleting a PPP Entity Page 30 22 ...
Страница 978: ...Displaying Link Status Page 31 18 ...
Страница 988: ...Displaying ISDN Configuration Entry Status Page 32 10 ...
Страница 1024: ...Backup Services Commands Page 34 14 ...
Страница 1062: ...Diagnostic Test Cable Schematics Page 36 24 ...
Страница 1072: ...Configuring a Switch with an MPX Page A 10 ...
Страница 1086: ...Page B 14 ...
Страница 1100: ...Page I 14 Index ...