6.7.1 Ensure Multiple External Time Servers are set

Information

At least two external NTP Servers should be configured

Rationale:
Keeping time settings consistent across a network is vital if log data is to be meaningful and usable in understanding faults and security incidents. Consistent time settings are also vital to the operation of some network protocols and services such as IPSec and 802.1x which may be critical to many networks.
To ensure that the time on your JUNOS router is consistent with other devices in your network, at least two NTP Servers external to the device should be configured.
Although NTP provides for a Peer to Peer type implementation, where individual time servers are not specified and methods such as broadcast and multicast are utilized to synchronize time between hosts, in almost all real world cases a Server / Client model should be used for network devices - even if multicast or broadcast methods are used for other types of hosts. Using specified time sources allows you to better secure, monitor and manage your NTP implementation; simplifying debugging and allowing tighter control of NTP traffic.
Having multiple NTP servers ensures fault tolerance and also protects against mis-configured or compromised servers causing radical time changes, something an attacker may want to achieve to cover their tracks or conduct replay attacks.

Solution

Configure at least one External NTP Server using the following commands under the [edit system] hierarchy;
[edit system]
user@host#set ntp server <Servers IP>

Default Value:
By default Juniper routers do not have NTP servers configured.

See Also

https://workbench.cisecurity.org/files/2278

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-8(1), CSCv7|6.1

Plugin: Juniper

Control ID: d330df37d39b798e9e9ff2d0bd43943ef780a691e7f16da1100c87782702409f