cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
11292
Views
11
Helpful
3
Replies

NTP Access Lists

Craddockc
Level 3
Level 3

Community,

 

Im a little confused about where the NTP ACL's need to be applied. Everything im reading is making it sound like the ACL's need to be applied to the Servers that the clients are syncing their time to, is this correct? I would like to apply ACL's to my client network devices that define only the servers theyre allowed to sync to but the options of "peer" "server" "serve-only" and "query-only" make it sound like these are only server side options. Would I have to use authentication instead on the clients to define which servers the client devices are allowed to sync their time to? Thanks.

1 Accepted Solution

Accepted Solutions

HI, 

That is correct, but you have to remember that if your clients are routers or switches, they will act as servers themselves if a client points to them. If you would like to make your NTP infrastructure secure, you will need a deny  access list on  the routers and switches using the "peer" "server" "serve-only" and "query-only" keywords.

 

Hope this helps

 

Thanks

John

**Please rate posts you find helpful**

View solution in original post

3 Replies 3

johnd2310
Level 8
Level 8

Hi,

You can use the access list on the clients which protect the client from serving NTP or responding to queries. 

You specify the servers cleints are allowed to sync to using the "server" command. e.g.

ntp server 192.168.1.1

ntp server 192.168.1.2 

The above restricts the client to sync to servers 192.168.1.1 and 192.168.1.2 only.

 

thanks

John

**Please rate posts you find helpful**

John,

 

Thanks for the reply! This makes sense. The client isnt going to sync to anything thats not explicitly configured so no need for a client side ACL defining the servers. However, the servers need ACL's to control which clients can sync to it because there is no way to specify that in the running config. Does this sound correct? Thanks.

HI, 

That is correct, but you have to remember that if your clients are routers or switches, they will act as servers themselves if a client points to them. If you would like to make your NTP infrastructure secure, you will need a deny  access list on  the routers and switches using the "peer" "server" "serve-only" and "query-only" keywords.

 

Hope this helps

 

Thanks

John

**Please rate posts you find helpful**