zoukankan      html  css  js  c++  java
  • CentOS 6.3下NTP服务安装和配置

    测试环境:

    NTPserver 192.168.1.252

    NTPclient 192.168.1.251

    准备工作:

    关闭selinux:

    vi /etc/selinux/config

    SELINUX=disabled

    关闭iptables:

    service iptables stop

    chkconfig iptables off

    一.安装NTP软件包:

    yum -y install ntp /*yum安装NTP服务*/

    chkconfig --add ntpd /*添加NTP*/

    chkconfig ntpd on /*开机自启动NTP*/

    二.修改NTP配置文件:

    vi /etc/ntp.conf
    ***************************************************************

    # For more information about this file, see the man pages
    # ntp.conf(5), ntp_acc(5), ntp_auth(5), ntp_clock(5), ntp_misc(5), ntp_mon(5).

    driftfile /var/lib/ntp/drift
    restrict default ignore 设置默认策略为拒绝所有访问方式的请求
    # Permit time synchronization with our time source, but do not
    # permit the source to query or modify the service on this system.
    restrict default kod nomodify notrap nopeer noquery
    restrict -6 default kod nomodify notrap nopeer noquery

    # Permit all access over the loopback interface. This could
    # be tightened as well, but to do so would effect some of
    # the administrative functions.
    restrict 127.0.0.1
    restrict -6 ::1

    # Hosts on local network are less restricted.
    restrict 192.168.1.0 mask 255.255.255.0 nomodify notrap 允许局域网内机器同步时间

    # Use public servers from the pool.ntp.org project.
    # Please consider joining the pool (http://www.pool.ntp.org/join.html).
    server 0.CentOS.pool.ntp.org
    server 1.centos.pool.ntp.org 设置同步服务器
    server 2.centos.pool.ntp.org

    #broadcast 192.168.1.255 autokey # broadcast server
    #broadcastclient # broadcast client
    #broadcast 224.0.1.1 autokey # multicast server
    #multicastclient 224.0.1.1 # multicast client
    #manycastserver 239.255.254.254 # manycast server
    #manycastclient 239.255.254.254 autokey # manycast client

    restrict 0.centos.pool.ntp.org nomodify notrap noquery
    restrict 1.centos.pool.ntp.org nomodify notrap noquery 允许与上层服务器同步时间
    restrict 2.centos.pool.ntp.org nomodify notrap noquery

    # Undisciplined Local Clock. This is a fake driver intended for backup
    # and when no outside source of synchronized time is available.
    server 127.127.1.0 # local clock
    fudge 127.127.1.0 stratum 10 外界同步源无法联系时,使用本地时间为同步服务

    # Enable public key cryptography.
    #crypto

    includefile /etc/ntp/crypto/pw

    # Key file containing the keys and key identifiers used when operating
    # with symmetric key cryptography.
    keys /etc/ntp/keys

    # Specify the key identifiers which are trusted.
    #trustedkey 4 8 42

    # Specify the key identifier to use with the ntpdc utility.
    #requestkey 8

    # Specify the key identifier to use with the ntpq utility.
    #controlkey 8

    # Enable writing of statistics records.
    #statistics clockstats cryptostats loops

    ***************************************************************

  • 相关阅读:
    不用keytool,tomcat打开https
    sqlserver获取某一张表中的所有列中的最大长度
    不用keytool,tomcat打开https
    到底私钥和公钥哪个是用来加密 哪个是用来解密的
    空间支持php解压
    到底私钥和公钥哪个是用来加密 哪个是用来解密的
    sqlserver获取某一张表中的所有列中的最大长度
    数字签名(代码签名)流程
    功夫电影中非常经典(武术非常实用)
    数字签名(代码签名)流程
  • 原文地址:https://www.cnblogs.com/qingchen1984/p/3985792.html
Copyright © 2011-2022 走看看