Configuring Network Time Protocol
The device can be configured to sync with a Network Time Protocol (NTP) server. It supports time updates using NTP version 4. The device authenticates updates using an administrator-configured SHA-1 or SHA-256 symmetric key. The device rejects broadcast and multicast time updates by default without requiring any configuration. It does not place a limit on the number of NTP time sources that can be configured.
To configure the device in client mode, include the server statement and other statements
at the [edit system ntp] hierarchy level:
[edit system ntp] security-administrator@hostname:fips# server address key key-number version 4 prefer security-administrator@hostname:fips# authentication-key key-number type sha1|sha256 value key value security-administrator@hostname:fips# trusted-key trusted key-number
The above commands specify the address of the system acting as the time server. One specifies an address, not a hostname. The same command can be used to configure multiple NTP servers.
It also configures the authentication key sent in all messages sent to the time server,
using the key option. The key corresponds to the key number specified in the
authentication-key statement. By default, the device sends NTP version 4
packets to the time server. If more than one time server is configured, one server can be
marked as preferred by including the prefer option.
The following example shows how to configure the device to operate in client mode:
[edit system ntp] security-administrator@hostname:fips# authentication-key 12 type sha256 value "$9$TQFn/9t0OIcywY4oGU9At" security-administrator@hostname:fips# server 10.1.1.1 key 12 prefer security-administrator@hostname:fips# trusted-key 12
By default, NTP operates in an entirely unauthenticated manner. If a malicious attempt to influence the accuracy of a router or switch’s clock succeeds, it could have negative effects on system logging, make troubleshooting and intrusion detection more difficult, and impede other management functions.
For common criteria compliance, use trusted authentication using SHA1 or SHA256 as the message digest algorithm(s) to make sure that the NTP peer is trusted.
For IP version 4 (IPv4), one can specify the source address the TOE will use to access the network when it is sending NTP requests to the server.
To configure the specific source address that the request will always use, include the
source-address statement at the [edit system ntp]
hierarchy level. The source-address is a valid IP address configured on one
of the router or switch interfaces.
[edit system ntp] security-administrator@hostname:fips# set source-address source-address
For example:
[edit system ntp] security-administrator@hostname:fips# set source-address 10.1.4.3