Operation Manual – NTP
H3C S3100 Series Ethernet Switches
Chapter 1 NTP Configuration
1-12
z
synchronization
: Synchronization right. This level of right permits the peer device
to synchronize its clock to the local switch but does not permit the peer device to
perform control query.
z
server
: Server right. This level of right permits the peer device to perform
synchronization and control query to the local switch but does not permit the local
switch to synchronize its clock to the peer device.
z
peer
: Peer access. This level of right permits the peer device to perform
synchronization and control query to the local switch and also permits the local
switch to synchronize its clock to the peer device.
From the highest NTP service access-control right to the lowest one are
peer
,
server
,
synchronization
, and
query
. When a device receives an NTP request, it will perform
an access-control right match in this order and use the first matched right.
1.4.1 Configuration Prerequisites
Prior to configuring the NTP service access-control right to the local switch for peer
devices, you need to create and configure an ACL associated with the access-control
right. For the configuration of ACL, refer to
ACL Configuration
in
Security Volume
.
1.4.2 Configuration Procedure
Table 1-9
Configure the NTP service access-control right to the local device for peer
devices
Operation
Command…
Description
Enter system view
system-view
—
Configure the NTP
service access-control
right to the local switch for
peer devices
ntp-service access
{
peer
|
server
|
synchronization
|
query
}
acl-number
Optional
peer
by default
Note:
The access-control right mechanism provides only a minimum degree of security
protection for the local switch. A more secure method is identity authentication.
1.5 Configuring NTP Authentication
In networks with higher security requirements, the NTP authentication function must be
enabled to run NTP. Through password authentication on the client and the server, the
clock of the client is synchronized only to that of the server that passes the