Time Protocols

SNTP: Viewing, Selecting, and Configuring

This feature provides support for SNTP client authentication on HP ProCurve switches, which addresses security considerations when deploying SNTP in a network.

Requirements

The following must be configured to enable SNTP client authentication on the switch.

SNTP Client Authentication Support

Timesync mode must be SNTP. Use the timesync sntp command. (SNTP is disabled by default.)

SNTP must be in unicast or broadcast mode. See “Configuring Unicast and Broadcast Mode” on page 9-21.

The MD5 authentication mode must be selected.

An SNTP authentication key-identifier (key-id) must be configured on the switch and a value (key-value) must be provided for the authenti­ cation key. A maximum of 8 sets of key-idand key-valuecan be configured on the switch.

Among the keys that have been configured, one key or a set of keys must be configured as trusted. Only trusted keys will be used for SNTP authentication.

If the SNTP server requires authentication, one of the trusted keys has to be associated with the SNTP server.

 

SNTP client authentication must be enabled on the ProCurve switch.

 

If client authentication is disabled, packets are processed without

 

authentication. All of the above steps are necessary to enable authen­

 

tication on the client.

 

SNTP Server Authentication Support

 

 

Note

SNTP server is not supported on ProCurve products.

 

 

9-17