Usage of ntpq to query the NTP servers

If the host has the NTP service enable but don’t send any data to the query, the server is configured correctly.

But … if you send a query and get information back… the server is vulnerable to attacks. Obtain kernel information and other NTP server parameters. ntpq -pncrv IP   Example:

Secure NTP configuration

Tips: 1. Ensure you have the restrictions in ntp.conf

  2. Disable monitor to protect of the CVE-2013-5211 vulnerability

  3. Use “nomodify nopeer noquery notrap” for each IP and network your NTP  system connects or receive connections.

  Example NTP server configuration.

  Example NTP Client configuration


