EasyManuals Logo

HPE FlexNetwork 5130 HI SERIES User Manual

HPE FlexNetwork 5130 HI SERIES
378 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #118 background imageLoading...
Page #118 background image
109
query: Allows only NTP control queries from a peer device to the local device.
server: Allows time requests and NTP control queries, but does not allow the local device to
synchronize itself to a peer device.
synchronization: Allows only time requests from a system whose address passes the access list
criteria.
ipv6-acl-number: Specifies an IPv6 ACL by its number. The peer devices that match the IPv6 ACL
have the access right specified in the command. The ipv6-acl-number argument represents a basic
IPv6 ACL number in the range of 2000 to 2999 or an advanced IPv6 ACL number in the range of
3000 to 3999.
Usage guidelines
When the device receives an IPv6 NTP request, it matches the request against the access rights in
the order from the least restrictive to the most restrictive: peer, server, synchronization, and
query.
• If no IPv6 NTP access control is configured, the peer access right applies.
• If the IP address of the peer device matches a permit statement in an IPv6 ACL, the access
right is granted to the peer device. If a deny statement or no IPv6 ACL is matched, no access
right is granted.
• If no IPv6 ACL is specified for an access right or the IPv6 ACL specified for the access right is
not created, the access right is not granted.
• If none of the IPv6 ACLs specified for the access rights is created, the peer access right
applies.
• If none of the IPv6 ACLs specified for the access rights contains rules, no access right is
granted.
The ntp-service ipv6 acl command provides a minimum security method. NTP authentication is
more secure.
Examples
# Configure the peer devices on subnet 2001::1 to have full access to the local device.
<Sysname> system-view
[Sysname] acl ipv6 basic 2001
[Sysname-acl-ipv6-basic-2001] rule permit source 2001::1 64
[Sysname-acl-ipv6-basic-2001] quit
[Sysname] ntp-service ipv6 peer acl 2001
Related commands
ntp-service authentication enable
ntp-service authentication-keyid
ntp-service reliable authentication-keyid
ntp-service ipv6 dscp
Use ntp-service ipv6 dscp to set a DSCP value for IPv6 NTP packets.
Use undo ntp-service ipv6 dscp to restore the default.
Syntax
ntp-service ipv6 dscp dscp-value
undo ntp-service ipv6 dscp

Table of Contents

Other manuals for HPE FlexNetwork 5130 HI SERIES

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HPE FlexNetwork 5130 HI SERIES and is the answer not in the manual?

HPE FlexNetwork 5130 HI SERIES Specifications

General IconGeneral
BrandHPE
ModelFlexNetwork 5130 HI SERIES
CategorySwitch
LanguageEnglish

Related product manuals