121
Usage guidelines
You need to enable SNTP authentication in networks that require time synchronization security to
make sure SNTP clients are synchronized only to authenticated NTP servers.
To authenticate an NTP server, set an authentication key and specify it as a trusted key.
Examples
# Enable SNTP authentication.
<Sysname> system-view
[Sysname] sntp authentication enable
Related commands
sntp authentication-keyid
sntp reliable authentication-keyid
sntp authentication-keyid
Use
sntp authentication-keyid
to set an SNTP authentication key.
Use
undo sntp authentication-keyid
to remove the SNTP authentication key.
Syntax
sntp authentication-keyid
keyid
authentication-mode md5
{
cipher
|
simple
}
value
undo sntp authentication-keyid
keyid
Default
No SNTP authentication key is set.
Views
System view
Predefined user roles
network-admin
mdc-admin
Parameters
keyid
: Specifies a key ID to identify an authentication key, in the range of 1 to 4294967295.
authentication-mode
md5
value
: Uses the MD5 algorithm for key authentication.
simple
: Sets a plaintext authentication key.
cipher
: Sets a ciphertext authentication key.
value
: Specifies the MD5 authentication key string. If
simple
is specified, it is a string of 1 to 32
characters. If
cipher
is specified, it is a string of 1 to 73 characters.
Usage guidelines
You need to enable SNTP authentication in networks that require time synchronization security to
make sure SNTP clients are synchronized only to authenticated NTP servers.
Configure the same key ID and key value on the SNTP client and NTP server. Otherwise, the SNTP
client cannot be synchronized to the NTP server. After you configure an SNTP authentication key,
use the
sntp reliable authentication-keyid
command to set it as a trusted key. The key
automatically changes to untrusted after you delete the key. In this case, you do not need to execute
the
undo sntp-service reliable authentication-keyid
command.
You can set a maximum of 128 keys by executing the command.
Содержание FlexNetwork 7500 Series
Страница 238: ...229 Sysname ...
Страница 420: ...411 Related commands packet capture ...
Страница 430: ...421 U url 78 username 79 user role 249 V version 80 vpn instance 81 W Websites 415 X xml 227 ...