cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
971
Views
1
Helpful
11
Replies

NTP Control Queries

Bilal Al-Sardar
Level 1
Level 1

Hello Team!,

I would like to know if it is possible to disable NTP control queries on Catalyst switches and ISR routers.

 

Thanks,

 

11 Replies 11

balaji.bandi
Hall of Fame
Hall of Fame

what is the use case here - as i read part of my cert journey  INE have good blog :

https://ine.com/blog/2008-07-28-ntp-access-control

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

NTP is already configured with multiple server IPs associated with a key and MD5 authentication. we had a security assessment and we received a report that recommends disabling "NTP control queries". I have tried to use an ACL but that caused an "unsynchronised" status.

Without config ntp server and ntp peer

SW or ISR not send any queries.

NTP is already configured with multiple servers.

what i am thinking,

If you have ACL which source and destination for NTP traffil allowed, that should be ok

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Tried this method, but i keep getting (unsynchronized) status.

Hi

I think alot 

There are two ways I think 

1- config acl with query-only

This send ntp control for only server list in acl

2- change the mode to ntp broadcast' which is as silent mode in which server send ntp messages without any ntp from client/peer

Tried this method, but it keeps getting (unsynchronized) status.

Which one you try 

Acl with query only OR broadcast?

ACL only. Broadcast is not allowed in the environment.

M02@rt37
VIP
VIP

Hello @Bilal Al-Sardar,

do not config NTP on your equipement !

Best regards
.ı|ı.ı|ı. If This Helps, Please Rate .ı|ı.ı|ı.
Review Cisco Networking for a $25 gift card