6.7.2 Ensure NTP Boot-Server is set

Information

At least one server should be configured for the router to update its time on boot.

Rationale:
When the router boots or when a new Routing Engine is installed its time may have drifted or be set beyond the maximum amount where periodic updates can return it to the correct time, resulting in the correct time never being set.
To prevent this situation; a Boot Server should be set from which the JUNOS device will obtain its time as it loads.
Because the ntpdateutility, which contacts the Boot Server, runs prior to many of the other core demons, such as rpd, the Boot Server should be reachable from the device's management interface (fxp0 on most routers, 'em0' or 'me0' on some other platforms) without any Routing Protocol learned routes or Tunnels being available. For this reason, the Boot Server is often a different NTP server to that used during normal operation, potentially just being the management interface of another router in the same management subnet.

Solution

To configure an NTP Boot Server, enter the following command from the [edit system ntp] hierarchy;
[edit system ntp]
user@host#set ntp boot-server <Server IP>

Default Value:
By default Juniper routers do not have NTP configured.

See Also

https://workbench.cisecurity.org/files/2278

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-8(1), CSCv7|6.1

Plugin: Juniper

Control ID: fa41596a0307e5b2ba66a94209654d667cf4abfe4a9ecc476cbc09dd8cccff2e