372
C
35: NTP C
HAPTER
Configuring NTP
Implementation
Modes
Configuring NTP
Server/Client Mode
ONFIGURATION
A Switch 4210 can work in one of the following NTP modes:
"Configuring NTP Server/Client Mode"
■
"Configuring the NTP Symmetric Peer Mode"
■
"Configuring NTP Broadcast Mode"
■
"Configuring NTP Multicast Mode"
■
n
To protect unused sockets against attacks by malicious users and improve security,
the 3Com Switch 4210 Family provides the following functions:
UDP port 123 is opened only when the NTP feature is enabled.
■
UDP port 123 is closed as the NTP feature is disabled.
■
These functions are implemented as follows:
Execution of one of the ntp-service unicast-server, ntp-service
■
unicast-peer, ntp-service broadcast-client, ntp-service broadcast-server,
ntp-service multicast-client, and ntp-service multicast-server commands
enables the NTP feature and opens UDP port 123 at the same time.
Execution of the undo form of one of the above six commands disables all
■
implementation modes of the NTP feature and closes UDP port 123 at the
same time.
For switches working in the server/client mode, you only need to perform
configurations on the clients, and not on the servers.
Table 283 Configure an NTP client
Operation
Enter system view
Configure an NTP client
n
The remote server specified by remote-ip or server-name serves as the NTP
■
server, and the local switch serves as the NTP client. The clock of the NTP client
will be synchronized by but will not synchronize that of the NTP server.
remote-ip cannot be a broadcast address, a multicast address or the IP address
■
of the local clock.
After you specify an interface for sending NTP messages through the
■
source-interface keyword, the source IP address of the NTP message will be
configured as the primary IP address of the specified interface.
A switch can act as a server to synchronize the clock of other switches only
■
after its clock has been synchronized. If the clock of a server has a stratum level
lower than or equal to that of a client's clock, the client will not synchronize its
clock to the server's.
You can configure multiple servers by repeating the ntp-service
■
unicast-server command. The client will choose the optimal reference source.
Command
system-view
ntp-service unicast-server {
remote-ip | server-name } [
authentication-keyid key-id
| priority | source-interface
Vlan-interface vlan-id |
version number ]*
Description
-
Required
By default, the switch is not
configured to work in the NTP
client mode.