HP 6125XLG R2306-HP 6125XLG Blade Switch Network Management and Monitoring Con - Page 55

Configuring SNTP authentication

Page 55 highlights

Step 2. Specify an NTP server for the device. Command • For IPv4: sntp unicast-server { ip-address | server-name } [ vpn-instance vpn-instance-name ] [ authentication-keyid keyid | source interface-type interface-number | version number ] * • For IPv6: sntp ipv6 unicast-server { ipv6-address | server-name } [ vpn-instance vpn-instance-name ] [ authentication-keyid keyid | source interface-type interface-number ] * Remarks By default, no NTP server is specified for the device. Repeat this step to specify multiple NTP servers. To use authentication, you must specify the authentication-keyid keyid option. To use an NTP server as the time source, make sure its clock has been synchronized. If the stratum level of the NTP server is greater than or equal to that of the client, the client does not synchronize with the NTP server. Configuring SNTP authentication SNTP authentication makes sure an SNTP client is synchronized only to an authenticated trustworthy NTP server. To make sure SNTP authentication can work, follow these guidelines on configuring SNTP authentication: • Enable authentication on both the NTP server and the SNTP client. • Configure the SNTP client with the same authentication key ID and key value as the NTP server, and specify the key as a trusted key on both the NTP server and the SNTP client. For information about configuring NTP authentication on an NTP server, see "Configuring NTP." • Associate the specified key with the specific NTP server on the SNTP client. With authentication disabled, the SNTP client can synchronize with the NTP server regardless of whether the NTP server is enabled with authentication. To configure SNTP authentication on the SNTP client: Step 1. Enter system view. 2. Enable SNTP authentication. 3. Configure an SNTP authentication key. 4. Specify the key as a trusted key. Command system-view sntp authentication enable sntp authentication-keyid keyid authentication-mode md5 { cipher | simple } value sntp reliable authentication-keyid keyid Remarks N/A By default, SNTP authentication is disabled. By default, no SNTP authentication key is configured. By default, no trusted key is specified. 49

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148

49
Step
Command
Remarks
2.
Specify an NTP server for the
device.
For IPv4:
sntp unicast-server
{
ip-address
|
server-name
}
[
vpn-instance
vpn-instance-name
]
[
authentication-keyid
keyid
|
source
interface-type
interface-number
|
version
number
] *
For IPv6:
sntp ipv6 unicast-server
{
ipv6-address
|
server-name
}
[
vpn-instance
vpn-instance-name
]
[
authentication-keyid
keyid
|
source
interface-type
interface-number
] *
By default, no NTP server is
specified for the device.
Repeat this step to specify multiple
NTP servers.
To use authentication, you must
specify the
authentication-keyid
keyid
option.
To use an NTP server as the time source, make sure its clock has been synchronized. If the stratum level
of the NTP server is greater than or equal to that of the client, the client does not synchronize with the NTP
server.
Configuring SNTP authentication
SNTP authentication makes sure an SNTP client is synchronized only to an authenticated trustworthy NTP
server.
To make sure SNTP authentication can work, follow these guidelines on configuring SNTP authentication:
Enable authentication on both the NTP server and the SNTP client.
Configure the SNTP client with the same authentication key ID and key value as the NTP server, and
specify the key as a trusted key on both the NTP server and the SNTP client. For information about
configuring NTP authentication on an NTP server, see "
Configuring NTP
."
Associate the specified key with the specific NTP server on the SNTP client.
With authentication disabled, the SNTP client can synchronize with the NTP server regardless of whether
the NTP server is enabled with authentication.
To configure SNTP authentication on the SNTP client:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable SNTP authentication.
sntp authentication enable
By default, SNTP authentication is
disabled.
3.
Configure an SNTP
authentication key.
sntp authentication-keyid
keyid
authentication-mode md5
{
cipher
|
simple
}
value
By default, no SNTP authentication
key is configured.
4.
Specify the key as a trusted
key.
sntp reliable authentication-keyid
keyid
By default, no trusted key is
specified.