6.7.3 Ensure NTP Boot-Server is set

Information

An NTP Boot-Server should be configured for the router to update its time on boot.

Rationale:

When the router boots or when a new Routing Engine is installed its time may have drifted or be set beyond the maximum amount where periodic updates can return it to the correct time, resulting in the correct time never being set.

To prevent this situation; a Boot Server should be set from which the JUNOS device will obtain its time as it loads.

Because the ntpdate utility, which contacts the Boot Server, runs prior to many of the other core demons, such as rpd, the Boot Server should be reachable from the device's management interface (fxp0 on most routers, 'em0' or 'me0' on some other platforms) without any Routing Protocol learned routes or Tunnels being available.

For this reason, the Boot Server may often be a different NTP server to that used during normal operation, potentially just being the management interface of another router in the same management subnet.

A Boot Server should be specified wherever possible, however, reachability of an NTP Server or another network device through Out of Band Management is not possible in all deployment scenarios; therefore this Recommendation is given at Level 2 as additional equipment or cost may be required for implementation.

Impact:

If time is not synchronised between devices, log messages cannot readily be correlated to allow administrators to understand events on the network. In addition, many services such as IPSEC, PKI or 802.1x which rely on Encryption may not function correctly if time and date settings are not properly maintained.

Solution

To configure an NTP Boot Server, enter the following command from the [edit system ntp] hierarchy;

[edit system ntp]
user@host#set ntp boot-server <Server IP or Hostname>

Default Value:

By default Juniper routers do not have NTP servers configured and use locally managed time.

See Also

https://workbench.cisecurity.org/files/3069

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-8, CSCv7|6.1

Plugin: Juniper

Control ID: 3a5ecd2bae0fd4ce555869c613034bed010c64fd90d964882610e3decf2f15d5