1.1.4 Network Time Protocol

Information

EOS enables Network Time Protocol (ntp) on the switch by default, and time settings from any properly configured ntp server override the manual setting of the system clock.

ntp servers synchronize time settings of systems running an ntp client. The switch supports ntp versions 1 through 4, and uses version 4 by default.

Without synchronized time accurately correlating information between devices becomes difficult, if not impossible. If logs cannot be successfully compared between each of the routers, switches, and firewalls, it will be very difficult to determine the exact events that resulted in a network breach incident. NTP provides an efficient and scalable method for network elements to synchronize to an accurate time source. A trusted time source is important to ensure proper logging and correlation of events to a syslog server where forensic information can be gathered in addition to any information concerning potential threats. If possible it is recommended to configure more than one NTP server.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure one or more NTP servers. NTP should be provided via the management network.

switch(config)# ntp server vrf {management vrf} {Hostname|IPaddr} prefer
switch(config)# ntp server vrf {management vrf} {Hostname|IPaddr}

See Also

https://workbench.cisecurity.org/benchmarks/25683

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-8(1)

Plugin: Arista

Control ID: 006924fd3731b4cfc7e6b213f64e60de7cc9d3020d094df4281d77736f08d7b2