Details
Sets a NTP server for which authentication is enabled in order to receive time information
Rationale:
When authentication is not enabled, attackers can disguise as NTP servers and broadcast wrong time and it will be difficult to correlate events upon an incident. In some other cases, attackers can perform NTP DDoS attacks such as NTP Amplification. The trusted NTP server will be authenticated through the NTP authentication key.
Solution
Step 1: Acquire the authentication key ID
Step 2: Run the following to configure the trusted NTP server
hostname(config)# ntp server
Default Value:
Disabled by default
Supportive Information
The following resource is also helpful.
This security hardening control applies to the following category of controls within NIST 800-53: Configuration Management.This control applies to the following type of system Cisco.