From: Sam Munzani (sam@xxxxxxxxxx)
Date: Mon Jul 31 2000 - 11:51:21 GMT-3
Wrong. I have it working with NTP server command.
On Sun, 30 Jul 2000, Derek Small wrote:
> You cannot use the "ntp server" command if you want to do authentication. Us
e the "NTP peer" command on both server and client to get it to work correctly.
>
> Derek Small
> CCIE # 5832
> dwsmall@fatkid.com
>
>
> ----- Original Message -----
> From: John Conzone
> To: Simon Hopkins ; Andrew
> Cc: ccielab
> Sent: Sunday, July 30, 2000 4:09 PM
> Subject: Re: NTP authentication
>
>
> Simon, the problem is that if I enable authentication on the server sid
e, the clients still connect whether I specify authentication on the client or
not. I debug ntp auth and see NOTHING. I debug ntp packets and see the same w
hether I have authentication on or not.
> I'm thinking that if I enable authentication on the server then none of
the clients should be able to sync without authentication. Like OSPF or RIP2.
> I have searched CCO and TAC database for any complete NTP authenticatio
n configs and have found none. I find that curious. I can't find any, not even
partial using NTP authentication.
> ----- Original Message -----
> From: Simon Hopkins
> To: Andrew
> Cc: John Conzone ; ccielab
> Sent: Sunday, July 30, 2000 3:09 PM
> Subject: Re: NTP authentication
>
>
> A common problem is using the "ntp server x.x.x.x" command without the "k
ey"
> e.g
> ntp authenticate
> ntp trusted-key 1
> ntp authentication-key 1 md5 cisco
> ntp server x.x.x.x key 1
>
>
> Andrew wrote:
>
> Can you show us what configuration you are using?
> At 12:44 PM 7/30/00 -0400, John Conzone wrote:
>
> I have 6 routers, one as NTP Master 1 and the others as NTP serve
r X.X.X.X (ip of master).
> I have no problem getting the other 5 to pull time from the master an
d clocks all synch up.
> However, I cannot get authentication to work. The clients synch t
o the master regardless of whether authentication is on or not. I can't find an
y good examples of NTP authentication configuration. I'm sure I'm implementing
wrong. Any help?
> Thanks!
>
This archive was generated by hypermail 2.1.4 : Thu Jun 13 2002 - 08:24:00 GMT-3