To do…

 

Use the command…

 

Remarks

 

 

 

 

 

 

ntp-service

 

Required

 

 

 

Configure the NTP

 

 

By default, no NTP

 

 

 

 

authentication-keyid key-id

 

 

 

 

authentication key

 

 

authentication key is

 

 

 

 

authentication-model md5 value

 

 

 

 

 

 

 

 

configured.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Configure the specified key as

 

ntp-service reliable

 

Required

 

 

 

 

 

By default, no trusted key is

 

 

 

a trusted key

 

authentication-keyid key-id

 

 

 

 

 

 

configured.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Associat

Configure on the

 

ntp-service unicast-server

 

 

 

 

 

e the

client in the

{ remote-ip server-name }

 

Required

 

 

 

specified

server/client mode

 

authentication-keyid key-id

 

For the client in the NTP

 

 

 

key with

 

 

 

 

 

 

 

 

 

 

 

broadcast/multicast mode,

 

 

 

the

 

 

 

 

 

 

 

Configure on the

 

 

 

 

 

 

 

 

 

you just need to associate the

 

 

 

correspo

 

 

 

 

 

 

symmetric-active

 

ntp-service unicast-peer

 

specified key with the client

 

 

 

nding

 

 

 

 

 

peer in the

{ remote-ip peer-name }

 

on the corresponding server.

 

 

 

NTP

 

 

 

 

symmetric peer

authentication-keyid key-id

 

 

 

 

 

server

 

 

 

 

 

mode

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

z

z

NTP authentication requires that the authentication keys configured for the server and the client be the same. Besides, the authentication keys must be trusted keys. Otherwise, the clock of the client cannot be synchronized with that of the server.

In NTP server mode and NTP peer mode, you need to associate the specified key with the corresponding NTP server (symmetric-active peer) on the client (symmetric-passive peer). In these two modes, multiple NTP servers (symmetric-active peers) may be configured for a client/passive peer, and therefore, the authentication key is required to determine which NTP server the local clock is synchronized to.

Configuring NTP authentication on the server

Follow these steps to configure NTP authentication on the server:

To do…

Use the command…

Remarks

Enter system view

system-view

 

 

 

Enable NTP authentication

ntp-service authentication

Required

enable

Disabled by default.

 

 

 

 

Configure an NTP

ntp-service

Required

authentication-keyid key-id

By default, no NTP

authentication key

authentication-mode md5

authentication key is

 

value

configured.

 

 

 

 

 

Required

Configure the specified key as a

ntp-service reliable

By default, no trusted

trusted key

authentication-keyid key-id

authentication key is

 

 

configured.

 

 

 

Enter VLAN interface view

interface Vlan-interface vlan-id

 

1-12

 

Page 487
Image 487
3Com WX3000 operation manual Configuring NTP authentication on the server