Configuring Network Time Protocol

The device can be configured to sync with a Network Time Protocol (NTP) server. It supports time updates using NTP version 4. The device authenticates updates using an administrator-configured SHA-1 or SHA-256 symmetric key. The device rejects broadcast and multicast time updates by default without requiring any configuration. It does not place a limit on the number of NTP time sources that can be configured.

To configure the device in client mode, include the server statement and other statements at the [edit system ntp] hierarchy level:

The above commands specify the address of the system acting as the time server. One specifies an address, not a hostname. The same command can be used to configure multiple NTP servers.

It also configures the authentication key sent in all messages sent to the time server, using the key option. The key corresponds to the key number specified in the authentication-key statement. By default, the device sends NTP version 4 packets to the time server. If more than one time server is configured, one server can be marked as preferred by including the prefer option.

The following example shows how to configure the device to operate in client mode:

By default, NTP operates in an entirely unauthenticated manner. If a malicious attempt to influence the accuracy of a router or switch’s clock succeeds, it could have negative effects on system logging, make troubleshooting and intrusion detection more difficult, and impede other management functions.

For common criteria compliance, use trusted authentication using SHA1 or SHA256 as the message digest algorithm(s) to make sure that the NTP peer is trusted.

For IP version 4 (IPv4), one can specify the source address the TOE will use to access the network when it is sending NTP requests to the server.

To configure the specific source address that the request will always use, include the source-address statement at the [edit system ntp] hierarchy level. The source-address is a valid IP address configured on one of the router or switch interfaces.

For example: