10-16-2023 04:23 AM - last edited on 10-16-2023 04:33 AM by rupeshah
Hello Team!,
I would like to know if it is possible to disable NTP control queries on Catalyst switches and ISR routers.
Thanks,
10-16-2023 04:44 AM
what is the use case here - as i read part of my cert journey INE have good blog :
10-18-2023 04:00 AM
NTP is already configured with multiple server IPs associated with a key and MD5 authentication. we had a security assessment and we received a report that recommends disabling "NTP control queries". I have tried to use an ACL but that caused an "unsynchronised" status.
10-16-2023 04:46 AM
Without config ntp server and ntp peer
SW or ISR not send any queries.
10-18-2023 04:02 AM
NTP is already configured with multiple servers.
10-18-2023 07:47 AM
what i am thinking,
If you have ACL which source and destination for NTP traffil allowed, that should be ok
10-22-2023 01:59 AM
Tried this method, but i keep getting (unsynchronized) status.
10-18-2023 09:13 AM
Hi
I think alot
There are two ways I think
1- config acl with query-only
This send ntp control for only server list in acl
2- change the mode to ntp broadcast' which is as silent mode in which server send ntp messages without any ntp from client/peer
10-22-2023 02:00 AM
Tried this method, but it keeps getting (unsynchronized) status.
10-22-2023 02:35 AM
Which one you try
Acl with query only OR broadcast?
10-22-2023 05:06 AM
ACL only. Broadcast is not allowed in the environment.
10-16-2023 05:08 AM - edited 10-16-2023 08:44 AM
Hello @Bilal Al-Sardar,
do not config NTP on your equipement !
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide