HP 6125XLG R2306-HP 6125XLG Blade Switch Network Management and Monitoring Com - Page 34

ntp-service ipv6 acl, Examples, Syntax, Default, Views, Predefined user roes, Parameters

Page 34 highlights

Examples # Disable VLAN-interface 1 from receiving NTP messages. system-view [Sysname] interface vlan-interface 1 [Sysname-Vlan-interface1] ntp-service inbound disable ntp-service ipv6 acl Use ntp-service ipv6 acl to configure the access-control right for the peer devices to access the IPv6 NTP services of the local device. Use undo ntp-service ipv6 acl to remove the configured NTP service access-control right. Syntax ntp-service ipv6 { peer | query | server | synchronization } acl acl-number undo ntp-service ipv6 { peer | query | server | synchronization } acl acl-number Default The access-control right for the peer devices to access the IPv6 NTP services of the local device is peer. Views System view Predefined user roes network-admin Parameters peer: Allows time requests and NTP control queries (such as alarms, authentication status, and time server information) and allows the local device to synchronize itself to a peer device. query: Allows only NTP control queries from a peer device to the local device. server: Allows time requests and NTP control queries, but does not allow the local device to synchronize itself to a peer device. synchronization: Allows only time requests from a system whose address passes the access list criteria. acl acl-number: Specifies an ACL. The peer devices that match the ACL have the access right specified in this command. The acl-number argument represents a basic ACL number in the range of 2000 to 2999. Usage guidelines You can control IPv6 NTP access by using ACL. The access rights are in the following order, from least restrictive to most restrictive: peer, server, synchronization, and query. The device processes an NTP request by following these rules: • If no NTP access control is configured, peer is granted to the local device and peer devices. • If the IP address of the peer device matches a permit statement in an ACL for more than one access right, the least restrictive access right is granted to the peer device. If a deny statement or no ACL is matched, no access right is granted. • If no ACL is created for a specific access right, the associated access right is not granted. • If no ACL is created for any access right, peer is granted. 32

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207

32
Examples
# Disable VLAN-interface 1 from receiving NTP messages.
<Sysname> system-view
[Sysname] interface vlan-interface 1
[Sysname-Vlan-interface1] ntp-service inbound disable
ntp-service ipv6 acl
Use
ntp-service ipv6 acl
to configure the access-control right for the peer devices to access the IPv6 NTP
services of the local device.
Use
undo ntp-service ipv6 acl
to remove the configured NTP service access-control right.
Syntax
ntp-service ipv6
{
peer
|
query
|
server
|
synchronization
}
acl
acl-number
undo ntp-service ipv6
{
peer
|
query
|
server
|
synchronization
}
acl
acl-number
Default
The access-control right for the peer devices to access the IPv6 NTP services of the local device is
peer
.
Views
System view
Predefined user roes
network-admin
Parameters
peer
: Allows time requests and NTP control queries (such as alarms, authentication status, and time
server information) and allows the local device to synchronize itself to a peer device.
query
: Allows only NTP control queries from a peer device to the local device.
server
: Allows time requests and NTP control queries, but does not allow the local device to synchronize
itself to a peer device.
synchronization
: Allows only time requests from a system whose address passes the access list criteria.
acl
acl-number
: Specifies an ACL. The peer devices that match the ACL have the access right specified in
this command. The
acl-number argument
represents a basic ACL number in the range of 2000 to 2999.
Usage guidelines
You can control IPv6 NTP access by using ACL. The access rights are in the following order, from least
restrictive to most restrictive:
peer
,
server
,
synchronization
, and
query
.
The device processes an NTP request by following these rules:
If no NTP access control is configured,
peer
is granted to the local device and peer devices.
If the IP address of the peer device matches a
permit
statement in an ACL for more than one access
right, the least restrictive access right is granted to the peer device. If a
deny
statement or no ACL is
matched, no access right is granted.
If no ACL is created for a specific access right, the associated access right is not granted.
If no ACL is created for any access right,
peer
is granted.