Check: NET0812
Network - Firewall:
NET0812
(in versions v8 r25 through v8 r21)
Title
Network devices must use at least two NTP servers to synchronize time. (Cat III impact)
Discussion
Without synchronized time, accurately correlating information between devices becomes difficult, if not impossible. If logs cannot be successfully compared between each of the routers, switches, and firewalls, it will be very difficult to determine the exact events that resulted in a network breach incident. NTP provides an efficient and scalable method for network devices to synchronize to an accurate time source.
Check Content
Review the configuration and verify two NTP servers have been defined. If the device is not configured to use two separate NTP servers, this is a finding.
Fix Text
Configure the device to use two separate NTP servers.
Additional Identifiers
Rule ID:
Vulnerability ID: V-23747
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |