02-16-2025 08:46 PM
I am trying to correct an NTP vulnerability on two external Cisco routers and an FTD firepower device.
I was under the belief that the command 'no ntp allow mode control' would prevent mode 6 NTP packets and therefore a DoS attack.
However, I saw some conflicting information stating that the command actually disables the default 3 second delay on NTP control packets and would assist a DoS attack by allowing an uncontrolled flow of packets.
If anyone is able to help me understand what the command no ntp allow mode control actually does that would be great.
02-16-2025 11:01 PM
M.
02-17-2025 03:04 PM
Thanks. I did see that post but I still would feel better if there is some actual Cisco doco on what that command does, or someone who can confirm it works in the way I believe it to.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide