Enables the functionality that allows an appliance to authenticate that the time it obtains from an NTP server is from a known and trusted source. This functionality is enabled by default, but authentication keys must be configured.
When NTP authentication is enabled and configured, the system clock is updated only if a key ID in the incoming NTP packet matches a key ID configured on the appliance, and if that key ID is mapped to the same MD5 or SHA1 hash value stored on both the NTP server and the appliance. If the key ID/value pair on the NTP server and appliance do not match, the clock is not updated. For details, see the System Administration Guide.
Syntax
[no] ntp authentication enable
Parameters
no
Use the no form of this command to disable NTP authentication.
Example
The following example enables NTP authentication. The command output shows that the functionality is enabled, but the keys are not configured.
hostname (config) # ntp authentication enable hostname (config) # show ntp configured NTP enabled: yes NTP Authentication enabled: yes NTP server 0.acme.pool.ntp.org Enabled: yes NTP version: 4 Key: none NTP server 0.acme.pool.ntp.org Enabled: yes NTP version: 4 Key: none
User role
Admin
Command mode
Config
Supported appliances
This command was released as follows:
Email Security — Server: Release 7.8.0
Network Security: Release 7.9
Central Management System: Release 7.9
Intelligent Virtual Execution - Server: Release 7.9