HP 6125G HP 6125G & 6125G/XG Blade Switches Network Management and Mon - Page 27

Configuration prerequisites, Configuring NTP authentication

Page 27 highlights

Configuration prerequisites Before you configure the NTP service access-control right to the local device, create and configure an ACL associated with the access-control right. For more information about ACLs, see ACL and QoS Configuration Guide. Configuration procedure To configure the NTP service access-control right to the local device: Step Command Remarks 1. Enter system view. system-view N/A 2. Configure the NTP service access-control right for a peer device to access the local device. ntp-service access { peer | query | server | synchronization } acl-number The default is peer. Configuring NTP authentication Enable NTP authentication for a system running NTP in a network where there is a high security demand. NTP authentication enhances network security by using client-server key authentication, which prohibits a client from synchronizing with a device that fails authentication. To configure NTP authentication, do the following: • Enable NTP authentication • Configure an authentication key • Configure the key as a trusted key • Associate the specified key with an NTP server or a symmetric peer These tasks are required. If any task is omitted, NTP authentication cannot function. Configuring NTP authentication in client/server mode Follow these instructions to configure NTP authentication in client/server mode: • A client can synchronize to the server only when you configure all the required tasks on both the client and server. • On the client, if NTP authentication is not enabled or no key is specified to associate with the NTP server, the client is not authenticated. No matter whether NTP authentication is enabled or not on the server, the clock synchronization between the server and client can be performed. • On the client, if NTP authentication is enabled and a key is specified to associate with the NTP server, but the key is not a trusted key, the client does not synchronize to the server no matter whether NTP authentication is enabled or not on the server. Configuring NTP authentication for client Step 1. Enter system view. Command system-view Remarks N/A 20

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157

20
Configuration prerequisites
Before you configure the NTP service access-control right to the local device, create and configure an
ACL associated with the access-control right. For more information about ACLs, see
ACL and QoS
Configuration Guide
.
Configuration procedure
To configure the NTP service access-control right to the local device:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Configure the NTP service
access-control right for a peer
device to access the local
device.
ntp-service access
{
peer
|
query
|
server
|
synchronization
}
acl-number
The default is
peer
.
Configuring NTP authentication
Enable NTP authentication for a system running NTP in a network where there is a high security demand.
NTP authentication enhances network security by using client-server key authentication, which prohibits
a client from synchronizing with a device that fails authentication.
To configure NTP authentication, do the following:
Enable NTP authentication
Configure an authentication key
Configure the key as a trusted key
Associate the specified key with an NTP server or a symmetric peer
These tasks are required. If any task is omitted, NTP authentication cannot function.
Configuring NTP authentication in client/server mode
Follow these instructions to configure NTP authentication in client/server mode:
A client can synchronize to the server only when you configure all the required tasks on both the
client and server.
On the client, if NTP authentication is not enabled or no key is specified to associate with the NTP
server, the client is not authenticated. No matter whether NTP authentication is enabled or not on
the server, the clock synchronization between the server and client can be performed.
On the client, if NTP authentication is enabled and a key is specified to associate with the NTP
server, but the key is not a trusted key, the client does not synchronize to the server no matter whether
NTP authentication is enabled or not on the server.
Configuring NTP authentication for client
Step
Command
Remarks
1.
Enter system view.
system-view
N/A