2.3.2 Set 'ip address' for 'ntp server'

Information

Use this command if you want to allow the system to synchronize the system software clock with the specified NTP server.

To ensure that the time on your Cisco router is consistent with other devices in your network, at least two (and preferably at least three) NTP Server/s external to the router should be configured.

Ensure you also configure consistent timezone and daylight savings time setting for all devices. For simplicity, the default of Coordinated Universal Time (UTC).

Solution

Configure at least one external NTP Server using the following commands

hostname(config)#ntp server {ntp-server_ip_address}
or
hostname(config)#ntp server {ntp server vrf [vrf name] ip address}

Impact:

Organizations should establish multiple Network Time Protocol (NTP) hosts to set consistent time across the enterprise. Enabling the 'ntp server ip address' enforces encrypted authentication between NTP hosts.

See Also

https://workbench.cisecurity.org/benchmarks/12917

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-7, 800-53|AU-8, CSCv7|6.1

Plugin: Cisco

Control ID: 8dee748011339236db05dd53952a0a8505b6e33bd3dcb47b7f11a266541f3aab