Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Permit time synchronization with our time source, but do not
- # permit the source to query or modify the service on this system.
- #===# this restricts who can talk to this server to obtain NTP information
- restrict default kod nomodify notrap nopeer noquery
- restrict -6 default kod nomodify notrap nopeer noquery
- # Permit all access over the loopback interface. This could
- # be tightened as well, but to do so would effect some of
- # the administrative functions.
- #===# self-explanatory
- restrict 127.0.0.1
- restrict -6 ::1
- # Use Xen's public servers.
- #===# This is in case your organization does not have its own internal NTP servers.
- broadcast 192.168.0.255 key 42 # broadcast server
- broadcastclient # broadcast client
- #broadcast 224.0.1.1 key 42 # multicast server
- #multicastclient 224.0.1.1 # multicast client
- #manycastserver 239.255.254.254 # manycast server
- #manycastclient 239.255.254.254 key 42 # manycast client
- # Undisciplined Local Clock. This is a fake driver intended for backup
- # and when no outside source of synchronized time is available.
- #server 127.127.1.0 # local clock
- #===# I add this to force the local machine to have a low stratum compared to external NTP servers.
- fudge 127.127.1.0 stratum 10
- # Drift file. Put this in a directory which the daemon can write to.
- # No symbolic links allowed, either, since the daemon updates the file
- # by creating a temporary in the same directory and then rename()'ing
- # it to the file.
- #===# This is where your machine stores its drift file, which is the estimated clock frequency error
- driftfile /var/lib/ntp/drift
- # Enable public key cryptography.
- #crypto
- includefile /etc/ntp/crypto/pw
- # Key file containing the keys and key identifiers used when operating
- # with symmetric key cryptography.
- keys /etc/ntp/keys
- # Specify the key identifiers which are trusted.
- #trustedkey 4 8 42
- # Specify the key identifier to use with the ntpdc utility.
- #requestkey 8
- # Specify the key identifier to use with the ntpq utility.
- #controlkey 8
- ### our local specifics ###
- #===# This deals with how self-modifying the local server can be to its own settings, as well
- #===# as not permitting external queries.
- #restrict X.Y.0.0 mask 255.255.0.0 nomodify notrap
- restrict 192.168.0.0 mask 255.255.255.0 nomodify notrap
- #===# A list of your local (organizational) NTP servers
- server 212.244.36.232 iburst
- server 0.centos.pool.ntp.org iburst
- server 1.centos.pool.ntp.org iburst
- server 2.centos.pool.ntp.org iburst
- server 3.centos.pool.ntp.org iburst
- #server 0.europe.pool.ntp.org iburst
- #server 1.europe.pool.ntp.org iburst
- #server 2.europe.pool.ntp.org iburst
- #server 3.europe.pool.ntp.org iburst
- #===# Here is the option to add local peers (within a subnet, server pool, etc.)
- # peers in case the standard NTP servers cannot be reached. These are the three XenServers in the pool.
- peer 192.168.0.177 burst iburst minpoll 4 maxpoll 4
- peer 192.168.0.178 burst iburst minpoll 4 maxpoll 4
- peer 192.168.0.179 burst iburst minpoll 4 maxpoll 4
- peer 192.168.0.180 burst iburst minpoll 4 maxpoll 4
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement