HP 6125G HP 6125G & 6125G/XG Blade Switches Network Management and Mon - Page 25

ntp-service authentication enable, Default level, Parameters, Description, Examples, Syntax

Page 25 highlights

Default level 3: Manage level Parameters peer: Permits full access. This level of right permits the peer devices to perform synchronization and control query to the local device and also permits the local device to synchronize its clock to that of a peer device. Control query refers to query of NTP status information, such as alarm information, authentication status, and clock source information. query: Permits control query. This level of right permits the peer devices to perform control query to the NTP service on the local device but does not permit a peer device to synchronize its clock to that of the local device. server: Permits server access and query. This level of right permits the peer devices to perform synchronization and control query to the local device but does not permit the local device to synchronize its clock to that of a peer device. synchronization: Permits server access only. This level of right permits a peer device to synchronize its clock to that of the local device but does not permit the peer devices to perform control query. acl-number: Specifies a basic ACL number, which ranges from 2000 to 2999. Description Use ntp-service access to configure the access-control right for the peer devices to access the NTP services of the local device. Use undo ntp-service access to remove the configured NTP service access-control right to the local device. By default, the access-control right for the peer devices to access the NTP services of the local device is set to peer. From the highest NTP service access-control right to the lowest one are peer, server, synchronization, and query. When a device receives an NTP request, it matches against the access-control right in this order and uses the first matched right. If no matched right is found, the device drops the NTP request. The ntp-service access command provides only a minimum degree of security protection. A more secure method is identity authentication. The related command is ntp-service authentication enable. Before specifying an ACL number in the ntp-service access command, make sure you have already created and configured this ACL. Examples # Configure the peer devices on subnet 10.10.0.0/16 to have the full access right to the local device. system-view [Sysname] acl number 2001 [Sysname-acl-basic-2001] rule permit source 10.10.0.0 0.0.255.255 [Sysname-acl-basic-2001] quit [Sysname] ntp-service access peer 2001 ntp-service authentication enable Syntax ntp-service authentication enable undo ntp-service authentication enable 19

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196

19
Default level
3: Manage level
Parameters
peer
: Permits full access. This level of right permits the peer devices to perform synchronization and
control query to the local device and also permits the local device to synchronize its clock to that of a peer
device. Control query refers to query of NTP status information, such as alarm information, authentication
status, and clock source information.
query
: Permits control query. This level of right permits the peer devices to perform control query to the
NTP service on the local device but does not permit a peer device to synchronize its clock to that of the
local device.
server
: Permits server access and query. This level of right permits the peer devices to perform
synchronization and control query to the local device but does not permit the local device to synchronize
its clock to that of a peer device.
synchronization
: Permits server access only. This level of right permits a peer device to synchronize its
clock to that of the local device but does not permit the peer devices to perform control query.
acl-number
: Specifies a basic ACL number, which ranges from 2000 to 2999.
Description
Use
ntp-service access
to configure the access-control right for the peer devices to access the NTP
services of the local device.
Use
undo ntp-service access
to remove the configured NTP service access-control right to the local
device.
By default, the access-control right for the peer devices to access the NTP services of the local device is
set to
peer
.
From the highest NTP service access-control right to the lowest one are
peer
,
server
,
synchronization
,
and
query
. When a device receives an NTP request, it matches against the access-control right in this
order and uses the first matched right. If no matched right is found, the device drops the NTP request.
The
ntp-service access
command provides only a minimum degree of security protection. A more secure
method is identity authentication. The related command is
ntp-service authentication enable
.
Before specifying an ACL number in the
ntp-service access
command, make sure you have already
created and configured this ACL.
Examples
# Configure the peer devices on subnet 10.10.0.0/16 to have the full access right to the local device.
<Sysname> system-view
[Sysname] acl number 2001
[Sysname-acl-basic-2001] rule permit source 10.10.0.0 0.0.255.255
[Sysname-acl-basic-2001] quit
[Sysname] ntp-service access peer 2001
ntp-service authentication enable
Syntax
ntp-service authentication enable
undo ntp-service authentication enable