ntp authentication enable

Prev Next

Enables the functionality that allows an appliance to authenticate that the time it obtains from an NTP server is from a known and trusted source. This functionality is enabled by default, but authentication keys must be configured.

When NTP authentication is enabled and configured, the system clock is updated only if a key ID in the incoming NTP packet matches a key ID configured on the appliance, and if that key ID is mapped to the same MD5 or SHA1 hash value stored on both the NTP server and the appliance. If the key ID/value pair on the NTP server and appliance do not match, the clock is not updated. For details, see the System Administration Guide.

Syntax

[no] ntp authentication enable

Parameters

no

Use the no form of this command to disable NTP authentication.

Example

The following example enables NTP authentication. The command output shows that the functionality is enabled, but the keys are not configured.

hostname (config) # ntp authentication enable
hostname (config) # show ntp configured
NTP enabled: yes
NTP Authentication enabled: yes
NTP server 0.acme.pool.ntp.org
  Enabled: yes
  NTP version: 4
  Key: none
NTP server 0.acme.pool.ntp.org
  Enabled: yes
  NTP version: 4
  Key: none

User role

Admin

Command mode

Config

Supported appliances

This command was released as follows:

  • Email Security — Server: Release 7.8.0

  • Network Security: Release 7.9

  • Central Management System: Release 7.9

  • Intelligent Virtual Execution - Server: Release 7.9