2.2.1.4 Set 'key' for each 'ntp server'

Information

Specifies the authentication key for NTP.

This authentication feature provides protection against accidentally synchronizing the ntp system to another system that is not trusted, because the other system must know the correct authentication key.

Solution

Configure each NTP Server to use a key ring using the following command.

IOSXR(config)#ntp server {ntp-server_ip_address} key {ntp_key_id}

Impact:

Organizations should establish three Network Time Protocol (NTP) hosts to set consistent time across the enterprise. Enabling the 'ntp server key' command enforces encrypted authentication between NTP hosts.

See Also

https://workbench.cisecurity.org/benchmarks/10473

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-7, 800-53|AU-8, CSCv7|6.1

Plugin: Cisco

Control ID: fd7ac8413efb5ee9d2c7998b043101b2d1fe6e93e4de0ced9200993473eaefd9