Q13IP Services
R1, acting as an NTP server, must have the following: - NTP authentication enabled - NTP packets sourced from interface Loopback 0 - NTP stratum 2 - NTP packets permitted only to client IP `209.165.200.225` How should R1 be configured?
← → navigate · a answer
Community votes
Discussion · 24
21
C looks right, this is an acl question.
10 is a standard acl number so A and D are wrong because they are extended acls.
NTP Master 2 makes the router an ntp server with stratum lvl 2.
C 7
Selected Answer: C
It can't be D because stratum is not a valid command.
6
I just realized, its 100% C because access-list 10 is a standard access-list, so specifying the protocol (udp) and destination address as any with the eq port number wouldn't be allowed.
C is the correct answer 100%
6
D has the command NTP stratum 2 (not a real command) it should be ntp master 2
5
Its not d, because access list 10 is standar and cannot configure ports on this
4
In my opinion, both C and D are correct answers, the only difference is that the access-list is more granular for D, meaning C is probably the better option.
C.
ntp authenticate
ntp authentication-key 2 md5 CISCO123
ntp source Loopback0
ntp access-group server-only 10
ntp master 2
access-list 10 permit 209.165.200.225
D.
ntp authenticate
ntp authentication-key 2 md5 CISCO123
ntp source Loopback0
ntp access-group server-only 10
ntp stratum 2
access-list 10 permit udp host 209.165.200.225 any eq 123
C 4
Selected Answer: C
explained below
3
Note ntp access-group serve-only is the correct command not server-only, but it's incorrect on every answer so it shouldn't matter.
Source: https://www.cisco.com/c/en/us/td/docs/routers/crs/software/crs_r4-0/system_management/command/reference/yr40crs_chapter10.html#wp1797670550:~:text=Allows%20only%20time%20requests.
A. Incorrect because sha1 isn't used for NTP authentication, must be MD5
ntp authenticate
ntp authentication-key 2 sha1 CISCO123
ntp source Loopback0
ntp access-group server-only 10
ntp master 2
access-list 10 permit udp host 209.165.200.225 any eq 123
3
B. Incorrect because it isn't using the NTP source command (uses ntp interface Loopback0) instead
ntp authenticate
ntp authentication-key 2 md5 CISCO123
ntp interface Loopback0
ntp access-group server-only 10
ntp stratum 2
access-list 10 permit 209.165.200.225
3
Good Catch !
3
try to login to any router, i think we cannot insert any stratum 2 , only master 2 can. and for ntp access-group server-only 10,, i should serve-only 10.. anyway Answer is C. agree with MDK94
2
The ACL granularity shouldn't be required since the acl is being applied to "serve-only" aka only allow time requests
Source: https://www.cisco.com/c/en/us/td/docs/routers/crs/software/crs_r4-0/system_management/command/reference/yr40crs_chapter10.html#wp1797670550:~:text=Allows%20only%20time%20requests.
2
you got a point but something pops up on my mind: the acl command is using standard numbered acl which ranges between 1 to 99 and as i studied the standard use only source ip so correct me if im wrong
2
Letter C ang sagot
2
C should be right
C 2
Selected Answer: C
ntp master <stratum-level> global configuration command is the right way to set the stratum value.
2
C is correct. standard access lists do not specifically filter by protocol.
2
D is correct NTP uses UDP port 514
1
I thought the question is about NTP, but it's NOT.
D 1
Selected Answer: D
Pretty sure it's D because it says Only NTP packets are allowed and on the access list command on D it specifies only allow traffic on port 123.
1
Also, since the NTP access group is set to server-only, time requests are allowed only from a device whose IP address meets the access list criteria.
1
But they missed the word "host" or the wildcard mask (0.0.0.0) in the ACL: access-list 10 permit 209.165.200.225
1
NTP stratus is NOT a valid cisco command. NTP master [stratum level]
1
C is the right answer. In D, the configuration of the startum value is wrong.