1.9.1.2 Ensure 'NTP authentication key' is configured correctly

Information

Sets the key used to authenticate NTP servers

Rationale:

When authentication is not enabled, attackers can disguise as NTP servers and broadcast wrong time and it will be difficult to correlate events upon an incident. In some other cases, attackers can perform NTP DDoS attacks such as NTP Amplification.

Solution

Step 1: Run the following to set the authentication key ID <key_id>

hostname(config)# ntp trusted-key <key_id>

Step 2: Run the following to configure the authentication key <authentication_key>

hostname(config)# ntp authentication-key <key_id> md5 <authentication_key>

Default Value:

Disabled by default

See Also

https://workbench.cisecurity.org/files/3294

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5, 800-53|IA-5(1), CSCv7|16.4

Plugin: Cisco

Control ID: 79407ce3e2513ff2106f23b5e1f61380e8bb50c432ded66b047899acaa33c3e9