syncserver s300 - marubun.co.jp€¦ · redundancy and versatility in network time servers, the...

8
SyncServer S300 High Performance, Enhanced Security GPS Network Time Server Setting new standards for security, reliability, redundancy and versatility in network time servers, the SyncServer ® S300 GPS Network Time Server is the solution for synchronizing the time on servers and workstations for large or expanding IT enterprises. Accurately synchronized clocks are critical for network log file accuracy, security, billing systems, electronic transactions, database integrity, VoIP, and many other essential applications. The high performance S300 continues the SyncServer legacy of being the easiest to set up and maintain network time servers in the world. The front panel is designed to quickly bring the server online with a few front panel keystrokes or DHCP. To fully configure the unit, use the very intuitive web interface or the step-by-step web based wizards for the most common operations. Once online, the S300 provides very reliable and secure network synchronization tech- nology by combining multi-port network in- terfaces with multiple time reference technology and enhanced security protocols. Support of the essential security and network protocols provide for easy management and seamless integration into your existing and future network. The S300 is the only time server available with a Gigabit Ethernet port plus three addi- tional 10/100Base-T ports. This translates into high availability and throughput to support hundreds of thousands of network KEY FEATURES Ultra High-Bandwidth NTP Time Server Stratum 1 Operation via GPS Satellites Gigabit Ethernet Port plus 3 Additional Independent 10/100Base-T Ports Internal Dial-up Modem for Time Reference Redundancy Stratum 2 Operation via NTP Servers RADIUS, NTPv4 Autokey, MD5 Authentication Secure Web-Based Management SSH, SSL, SCP, SNMP, Custom MIB, HTTPS, Telnet, and More High-Resolution Vacuum Fluorescent Display Full Numeric Keypad IPv6 and IPv4 Compatible Nanosecond Time Accuracy to UTC Dedicated Sysplex Timer Output Alarm Relays Single Satellite Timing Rubidium & OCXO Oscillator Upgrades Upgrade to Radio Broadcast Time Sync IEEE 1588 / PTP Grandmaster Option KEY BENEFITS Synchronize Thousands of Client, Server & Workstation Clocks Very Reliable and Secure Source of Time for Your Network Multiple NTP Ports for Easy Network Configuration and Adaptation Extremely Accurate Time Source for Network Synchronization Enhanced Network & Security Features Improve Network Log File Accuracy to Speed Network Fault Diagnosis and Forensics Access Multiple Time Sources for Reliable and Secure Time Very Easy to Install and Maintain Intuitive Web Interface for Easy Control & Maintenance clients while maintaining microsecond caliber NTP timestamp accuracy. These four completely independent ports provide the flexibility needed to easily adapt to different and changing network topologies and security requirements. The Stratum 1 level S300 derives its extremely accurate time directly from the atomic clocks aboard the GPS satellite system. For redundancy and time assurance, the S300 also includes an internal modem to connect directly to legal time provided by national time authorities. Reliability is further enhanced via Stratum 2 operation by retrieving time from other user-designated time servers. An optional AM radio will synchronize to national time broadcasts, which can be an alternative to GPS when GPS is not viable option. To further protect against the loss of accurate time, the S300 can be upgraded to an internal Rubidium atomic oscillator that keeps the S300 accurate to microseconds per day. IEEE 1588 / PTP Grandmaster functionality is also an available upgrade. The SyncServer S300 is your answer to bring- ing perfect timing to your network — securely, reliably and easily — and for many years to come.

Upload: phunghanh

Post on 04-Jun-2018

218 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: SyncServer S300 - marubun.co.jp€¦ · redundancy and versatility in network time servers, the SyncServer ® S300 GPS Network ... KEY BENEFITS • Synchronize ... Speed Network Fault

SyncServer S300High Performance, Enhanced Security GPS Network Time Server

Setting new standards for security, reliability,redundancy and versatility in network timeservers, the SyncServer® S300 GPS NetworkTime Server is the solution for synchronizingthe time on servers and workstations forlarge or expanding IT enterprises. Accuratelysynchronized clocks are critical for networklog file accuracy, security, billing systems,electronic transactions, database integrity,VoIP, and many other essential applications.

The high performance S300 continues theSyncServer legacy of being the easiest to setup and maintain network time servers in theworld. The front panel is designed to quicklybring the server online with a few front panelkeystrokes or DHCP. To fully configure theunit, use the very intuitive web interface orthe step-by-step web based wizards for themost common operations.

Once online, the S300 provides very reliableand secure network synchronization tech-nology by combining multi-port network in-terfaces with multiple time referencetechnology and enhanced security protocols.Support of the essential security and networkprotocols provide for easy management andseamless integration into your existing andfuture network.

The S300 is the only time server availablewith a Gigabit Ethernet port plus three addi-tional 10/100Base-T ports. This translatesinto high availability and throughput to support hundreds of thousands of network

KEY FEATURES• Ultra High-Bandwidth NTP Time Server

• Stratum 1 Operation via GPS Satellites

• Gigabit Ethernet Port plus 3 AdditionalIndependent 10/100Base-T Ports

• Internal Dial-up Modem for Time Reference Redundancy

• Stratum 2 Operation via NTP Servers

• RADIUS, NTPv4 Autokey, MD5Authentication

• Secure Web-Based Management

• SSH, SSL, SCP, SNMP, Custom MIB,HTTPS, Telnet, and More

• High-Resolution VacuumFluorescent Display

• Full Numeric Keypad

• IPv6 and IPv4 Compatible

• Nanosecond Time Accuracy to UTC

• Dedicated Sysplex Timer Output

• Alarm Relays

• Single Satellite Timing

• Rubidium & OCXO Oscillator Upgrades

• Upgrade to Radio BroadcastTime Sync

• IEEE 1588 / PTP Grandmaster Option

KEY BENEFITS• Synchronize Thousands of Client,

Server & Workstation Clocks

• Very Reliable and Secure Source ofTime for Your Network

• Multiple NTP Ports for Easy NetworkConfiguration and Adaptation

• Extremely Accurate Time Source forNetwork Synchronization

• Enhanced Network & Security Features

• Improve Network Log File Accuracy toSpeed Network Fault Diagnosis and Forensics

• Access Multiple Time Sources forReliable and Secure Time

• Very Easy to Install and Maintain

• Intuitive Web Interface for Easy Control & Maintenance

clients while maintaining microsecond caliberNTP timestamp accuracy. These four completely independent ports provide the flexibility needed to easily adapt to differentand changing network topologies and security requirements.

The Stratum 1 level S300 derives its extremelyaccurate time directly from the atomic clocksaboard the GPS satellite system. For redundancy and time assurance, the S300also includes an internal modem to connectdirectly to legal time provided by national timeauthorities. Reliability is further enhancedvia Stratum 2 operation by retrieving timefrom other user-designated time servers. Anoptional AM radio will synchronize to nationaltime broadcasts, which can be an alternativeto GPS when GPS is not viable option.

To further protect against the loss of accuratetime, the S300 can be upgraded to an internalRubidium atomic oscillator that keeps theS300 accurate to microseconds per day.IEEE 1588 / PTP Grandmaster functionalityis also an available upgrade.

The SyncServer S300 is your answer to bring-ing perfect timing to your network — securely,reliably and easily — and for many years to come.

Page 2: SyncServer S300 - marubun.co.jp€¦ · redundancy and versatility in network time servers, the SyncServer ® S300 GPS Network ... KEY BENEFITS • Synchronize ... Speed Network Fault

Examples of Network Timing Configu-rations

Basic configuration

Resilient configuration incorporating aRubidium Oscillator for improvedholdover performance.

Redundant, resilient and secureconfiguration incorporating a RubidiumOscillator in the primary server andpeering to another server for backupredundancy.

Resilient internal configuration. However,security, accuracy and reliability risksexist when peering with an external time server through the firewall.

S300 NETWORKING EXCELLENCE

Gigabit Ethernet for Unmatched High Performance with UnparalleledFlexibilityThe S300 has four dedicated and iso-lated Ethernet ports, one of which isGigabit Ethernet. These are connectedto a very high-speed microprocessorand a 50 nanosecond accurate clock toassure unparalleled high bandwidth NTPperformance. This more than meets theneed of servicing 7000 NTP requests persecond while maintaining microsecondcaliber timestamp accuracy.

Four Ports for Flexibility and SecurityMultiple ports provide the flexibility toadapt to different network topologiesas networks grow and change. An S300can be the single time source to syn-chronize clients that are on differentsubnets and different physical networks.It is also an ideal solution for synchro-nized time on in-band and out-of bandnetworks. Since each port is independent,

it can appear as though there are fourclocks available, even though there isonly a single time reference. In securitysensitive networks we suggest using oneport for maintenance and control func-tions and the other three ports for NTPtiming functions only. This way the controlport IP address information can be keptprivate and not distributed with the NTPaddresses. IP address access control listsfor each port also add enhanced security.

Extensive Protocol Support for Secureand Easy Network Integration andManagementAll of the expected network managementand monitoring protocols are standardin the S300. Secure access protocolssuch as RADIUS, SSL, HTTPS, SSH,along with legacy protocols such asDHCP and Telnet are included to provideyou a choice in server management.SNMP v3 with a custom MIB allows youto automatically monitor the S300 andbe advised of any important statuschanges. Any of these protocols can bequickly and easily disabled via the webbased management interface.

Futureproof Your NetworkThe S300 supports both IPv4 and IPv6.The S300 works whether you are usingIPv4, IPv4/IPv6 mixed-mode, or theIPv6 environment. This means your S300can scale with your network operationsand provide value for many years to come.

Automatic Software Upgrade Avail-ability NotificationThe S300 can periodically check theSymmetricom web site for newer ver-sions of firmware. If a newer version isavailable, an informational SNMP trapor email is sent along with a statusmessage in the web interface.

Point & Click Software UpgradesUpgrading the firmware in the S300 iseasy. Just browse to identify the firmwarefile and click the upload button. It is justas simple to backup and restore theserver configuration files. This intuitiveapproach simplifies server management.

Time Server Log Files A running log of activity and server configuration changes is maintained forlater reference.

2

Four network ports (including Gigabit) provide networkconfiguration flexibility and enhanced security. “Multi-ple” isolated and synchronized time servers can alsobe configured.

BEST PRACT ICES

• Always configure time clients to reference at least two timeservers.

• Two time servers provide redundant time source protectionfor time clients.

• Peering between time servers as-sures time continuity to timeclients if other time sources arenot available.

• Increase network security byserving time via ports GbE, 2 and 3 and reserving port 1 formanagement only.

Page 3: SyncServer S300 - marubun.co.jp€¦ · redundancy and versatility in network time servers, the SyncServer ® S300 GPS Network ... KEY BENEFITS • Synchronize ... Speed Network Fault

Control at Your Finger TipsThe interface on the S300 has been de-veloped and tested from a user per-spective. Keypad operation is quick andeasy when using the full numeric keypadand control keys. You can cycle throughdifferent time formats by pressing the[TIME] key or get detailed status infor-mation by pressing the [STATUS] key. TheS300 offers front panel menu controlvia the [MENU] button.

Quick and Easy InstallationThe S300 has been optimized for quicksetup via the keypad, requiring a mini-mum number of keystrokes. Just enterthe basic network parameters or selectDHCP and the unit is online. Once online,

the web interface is the best and easiestway to customize the time server.

Primary configuration and managementof the S300 is done via the intuitive andeasy-to-use web interface. It is the firsttime server that offers wizards to stream-line common setup and managementtasks. No other time server is availablewith such an effortless interface thatprovides intuitive navigation and depthof control.

Crisp, Bright Display and LEDsWhether you need to view time infor-mation close-up or far away, the 256x32high-resolution, variable intensity vac-uum fluorescent display provides highvisibility time and status in a variety ofuser selectable formats. The 1, 2 or 4line display of data makes for a crystalclear time display along with an inform-ative presentation of important config-uration information. The four LEDsprovide at-a-glance status of the currenttime reference, network connection status,NTP operational status and request ac-tivity, and any existing alarm situation.

SYNCSERVER S300

3

The full numeric keypad is the most efficient way tonavigate a menu driven interface. The [TIME] & [STATUS]buttons quickly display the most critical information.

Informative Status LEDs provide at-a-glance health ofthe network time server. The USB ports add additionalflexibility in back-up, restore and upgrade operations.

BEST PRACT ICES

• A full numeric keypad with a display makes for quick initialsetup and installation.

• Most interactions with a timeserver are remote and are bestserved with a full featured web interface and good SNMPmonitoring.

S300 ADVANCED AND FUNCTIONAL DESIGN Alarm Relays for Monitoring SystemsThe S300 features in-depth internalmonitoring, very flexible configurations,and external alarming. Alarm relays areone of several ways the unit can reportalarm conditions to an alarm monitoringsystem. One relay is activated if powerto the server is ever lost. The other relay is user configurable to activate if there is any major alarm, or anymajor/minor alarm.

• Very high-speed processor for superiorNTP server performance

• 7000 NTP requests per second withmicrosecond caliber time stamp accuracy

• Easily upgradeable firmware via webinterface (simple point & click)

• 12 channel GPS receiver with single satellite timing for urbancanyon environments

• High reliability, wide rangepower supply (AC or DC)

• No fan• No hard drive

• 2x Alarm Relays

• Modem forbackup timereference

• 4 ports: 1x Gigabit Ethernet,3x 10/100Base-T

• Radio Ready lowFrequency Radiooption

Optional Oscillators• Rubidium atomic oscillator option for 6

µs per day holdover accuracy• OCXO oscillator option for 1 ms per

day holdover accuracy

Crisp and bright vacuum fluorescent display offers highreadability both near and far. Characters can be large,medium or small. Intensity is user adjustable.

User configurable alarm relays for major/minor alarmsas well loss-of-power alarm relay.

• Optional IEEE 1588 / PTPGrandmaster hardwaretime stamping

Page 4: SyncServer S300 - marubun.co.jp€¦ · redundancy and versatility in network time servers, the SyncServer ® S300 GPS Network ... KEY BENEFITS • Synchronize ... Speed Network Fault

S300 FULL-FEATURED WEBINTERFACE

Intuitive, Easy-to-Use and SecureThe S300 is designed to have the webinterface be the primary status andcontrol console. It is organized into log-ical groupings such as Status, Network,Timing, etc. The tabbed panels offereasy exploration of features and easy

configuration of the server. Typical webinterface conventions are followed sothat operation is quickly mastered.Server access is password protected,with a choice of RADIUS authenticationand SSL encryption for maximum se-curity. The web interface is enabledonly through Port 1 so that the usermay choose to keep that port IP ad-dress exclusive and secure while serv-ing time protocols only from Ports 2, 3and/or GbE.

Wizards Speed Routine Server Config-uration TasksThe S300 includes wizards toguide you step-by-step throughthe more frequent or expectedoperations. From experiencewe know there are certain con-figuration activities that mostcustomers will, at some point,

want to perform with theserver. These include initial set-up, configuringtime source behaviors, back-upand restore operations,firmware upgrades, and more.The wizards make these oper-ations very easy. Like all sys-tems that include wizards,you can use the detailed con-

figuration pageselsewhere in the webinterface for customconfiguration of theserver.

Built-in Help SystemThe complete S300 manual isbuilt into the web interface.The manual opens in a separatebrowser window. It is organ-ized to match the control buttons and tabs so that in-formation is quickly and eas-ily found. On most pagesthere is a link directly to themanual page for that panel.

In addition there are context sensitiverollover descriptors of various featuresand tabs on any given panel.

Full System Status andLog FilesAn essential part of a time server isknowing the system status when youneed to. The S300 provides a semi-cus-tomizable green/red/orange light statuswith system messages for quick, at-a-glance information. Detailed status in-formation is available on all of themajor subsystems of the server via the

tabbed panels in the Status section.Any alarms or critical alerts are quicklyfound on the Alarm panel. To examineoperational events, the Log section ofthe web interface provides detailed list-ings of System, NTP, SNMP, HTTP, andEvent activities.

4

BEST PRACT ICES

• Configuring a time server isgenerally done once and seldomrepeated. For that reason it should be easy to configure and maintain.

• Consider the importance of quick and easy configurationback-up and restore operations,as well as the simplicity offirmware upgrades.

• Web based wizards save time and eliminate configuration conflicts. Easy configuration of advanced features is also im-portant.

• Turning on the auto-notificationof firmware update availability as-sures awareness of currentfirmware revisions.

Page 5: SyncServer S300 - marubun.co.jp€¦ · redundancy and versatility in network time servers, the SyncServer ® S300 GPS Network ... KEY BENEFITS • Synchronize ... Speed Network Fault

Synchronize to Legal Time SourcesServing time and synchronizing com-puters with time that is legally traceableto a national time standard is a require-ment for many organizations. The internaldial-up modem in the S300 and the op-tional AM radio both provide that directpath to a national time source, thus as-suring compliance.

Synchronize to Legal Timevia AM RadioAll SyncServer S300s are Radio Readyto accommodate an optional AM radio/antenna from Symmetricom. Nationaltime authorities in the USA, Europe andJapan (to name a few) all broadcast anAM time signal as an official source oftime, and many common devices rang-ing from wall clocks to wristwatchessynchronize to these broadcasts. TheAM radio becomes an alternative sourceof time to GPS. Users can also prioritizethe national radio signal ahead of theGPS signal as a time source and useGPS as a backup.

SYNCSERVER S300

Improved Time Reliability with Differ-ent Access PathsS300 time reliability starts with differentpaths to accurate time. Satellite, modem,and network provide redundancy shouldany one path become disconnected orunavailable. In addition, an optional AM radio provides a fourth path to timebroadcasts in many areas includingNorth America, Europe and Japan.

Use Dial-Up or AM Radio whenGPS is not an OptionOften a data center is located whereGPS is not a viable option, such as awindowless basement of a tall building.The built-in modem on the S300 canprovide dial-up access via analog phoneline to the national timesource maintained by manycountries. Calls are made pe-riodically and the frequency ofthe calls can be fixed or auto-matically optimized for accu-racy. When used in conjunctionwith an optional OCXO or Ru-bidium oscillator, this solutionoffers a stable and reliablesource of time for the networkto rely on. Similarly, the op-tional AM radio can synchronizeto national time broadcastsand works indoors or out-doors, anywhere or anytimethe AM signal is detected.

Multiple Time Sources Assure Reli-able TimeThe SyncServer S300 continually monitorsmultiple sources of time and synchro-nizes to the most reliable and accurate.The GPS satellites are the most accurateand widely available source of time, butnot the only source. The S300 can useNTP peering to monitor the time of othertime servers and the built-in modemcan periodically dial national time serv-ices. In the event the GPS signals be-come unavailable, the S300 willimmediately synchronize to the nextbest source of time. In all cases thenetwork administrator is notified im-mediately of any change in time reference status.

5

BEST PRACT ICES

• NTP protocol experts advise thattime servers should have at leasttwo sources of time, three is better, and four or more is best.

• Dial-up and radio broadcast signalsare also direct connections tolegal sources of time.

• Access and availability of timeshould be a consideration in every network design.

S300 TIME SOURCE REDUNDANCY

Internal modem and optional AM radio antenna provideaccess to national time sources for time reference re-dundancy.

Page 6: SyncServer S300 - marubun.co.jp€¦ · redundancy and versatility in network time servers, the SyncServer ® S300 GPS Network ... KEY BENEFITS • Synchronize ... Speed Network Fault

time servers (called “peering”). Thisprevents disruption of time service tothe network and the network adminis-trator is notified immediately via SNMPof the change in time reference status.A popular adjunct to peering is lettingthe time server operate in holdover(also called “free run” or “flywheel”)where the clock in the time server isallowed to drift if time sources are lost.The user can specify how far to let theclock drift in terms of estimated timeaccuracy before reverting to peering. Ifthe optional Rubidium oscillator is in-stalled, the S300 can flywheel for weeksand still be accurate to less than a mil-lisecond.

Time Cross-Checking for Peace ofMind ReliabilityThe S300 can time cross-check all reference time sources against at leasttwo other time servers. This protectsagainst an improperly operating GPSreceiver or radio that can subtly corruptthe time.

Flexible Control Over SystemTiming Inputs and OutputsBy protocol definition, the S300 servesNTP in the UTC timescale (or optionallyin GPS timescale). However, the S300can display local time rather than UTCon the front panel. The time can also beset manually with an override on theNTP alarms so that it behaves as thoughit is tracking a legitimate time source,even though it is actually in holdover.

Sysplex Timer for Mainframe SyncA dedicated Sysplex timer port outputsserial time strings for IBM mainframeSysplex systems. The Sysplex Timerprovides a common time reference acrossall the members of an IBM Sysplex.The Sysplex Timer is a key componentwhen systems on multiple CPCs shareaccess to the same data.

S300 PERFECT TIMING

Best-in-Class NTP AccuracyThe Stratum 1 level S300 derivesnanosecond accurate time directlyfrom the atomic clocks aboard the GPSsatellite system. By using an integrated,12-channel GPS receiver, every visiblesatellite can be tracked and used tomaintain accurate and reliable time. Evenin urban canyon environments wheresatellite visibility can be limited, singlesatellite tracking provides accurate timefrom as few as one intermittent satellite.If needed, the S300 can also tracksatellites using a window mounted an-tenna.

Ultra High Performance NTPThe S300 can effortlessly support hun-dreds of thousands of network clientswhile maintaining microsecond caliberNTP timestamp accuracy. NTP requestthroughput rates exceed 7000 requests/second while maintaining NTP timestampaccuracy. This easily translates into0.5-2 ms typical client synchronizationaccuracy on a LAN.

Multiple References, Peering orHoldoverIf the GPS reference signal is lost en-tirely, the S300 can automatically revertto alternate time sources and maintainStratum 1, or drop to Stratum 2 modeand retrieve time from other user-des-ignated internal or external network

1000.0

Holdover (days)

Tim

e Er

ror(

ms)

, log

sca

le

100.0

10.0

1.0

0.1

0.01 1E-05 10 20 30 40 50 60

TCXO OCXO Rubidium

Accumulated Drift Error by Oscillator Type

10000.0

BEST PRACT ICES

• Remember that accurate synchronization is directly relatedto how often the time clientsupdate their time from thetime server.

• Peering with other time serversis easy and provides a redundantsource of time as a fallback.

• The optional Rubidiumoscillator keeps the S300 ex-tremely accurate whileserving NTP in the event GPSservice is interrupted.

Oscillator Upgrades Improve HoldoverAccuracy and Save You Valuable TimeThe standard S300 is equipped with atemperature compensated crystal os-cillator (TCXO) that keeps the S300 ac-curate to nanoseconds when trackingGPS. However, if all time referencesare lost, thereby placing the server inholdover, the TCXO will soon drift awayfrom perfect. Upgrading the oscillatorimproves the holdover accuracy signifi-cantly. For example, consider the driftrates below:

Oscillator Holdover DriftTCXO 18 milliseconds per dayOCXO 1 millisecond per dayRubidium 6 microseconds per day

The value of the upgraded oscillator isthat if the GPS signal is lost the S300can continue to serve very accurate NTPtime. This provides the IT staff plenty oftime to correct the problem with nodegradation or disruption in networktime synchronization accuracy.

Optional IEEE 1588 / PTP Grandmaster Symmetricom makes it easy to addIEEE 1588 Precise Time Protocol (PTP)to any S300 SyncServer. All S300 SyncServers are factory ready for highaccuracy, hardware based PTP timestamping. When enabled, the PTPGrandmaster functions are very easy to configure via the web interface, andthe PTP protocol begins immediate operation.

Plot of time error in milliseconds accumulated duringholdover for different oscillator types. Note log scaleof Y-axis.

6

Page 7: SyncServer S300 - marubun.co.jp€¦ · redundancy and versatility in network time servers, the SyncServer ® S300 GPS Network ... KEY BENEFITS • Synchronize ... Speed Network Fault

SYNCSERVER S300

S300 UNRIVALED SECURITY

A Security ArchitectureThe S300 is carefully architected forsecurity via the multiport configuration.The web based management interfaceis enabled only through Port 1 so thatthe administrator may choose to keepthat port IP address private and secure.Only the time protocols can be servedvia Ports 2, 3 and/or GbE. Time protocolscan also be served from Port 1.

Management Access SecurityAccess to the web interface can beconfigured to pass through a variety ofsecurity measures including accesscontrol lists, passwords, RADIUS au-thentication, and SSL encryption formaximum security. RADIUS in particularprovides excellent security and easypassword management, particularlywhen there are multiple administratorsthat need access to the server. Individualprotocols such as telnet, SSH, etc., canbe disabled to further reduceopen ports and running dae-mons in the server. Locally thekeypad on the server can bepassword protected to preventtampering.

User Access SecurityAside from configuring themultiple ports for differentnetwork segments, unique ac-cess control lists per port cangovern server response toclient requests for time.

Server/Client AuthenticationAuthentication is valuable to as-sure that time is being retrievedfrom the correct time server andnot being spoofed in somewayby an imposter or man-in-the-middle. The S300 supports thetwo NTP authentication proto-cols, MD5 and Autokey. Gener-ally, authentication is usedbetween critical time clientsand the time server or between

NTP peers across a WANwhere trust is very im-portant. MD5 symmetric keycryptography is reasonably easyto deploy between clients andservers and is used to verify NTPpacket integrity. Symmetricom’sstate-of-the-art Autokey imple-mentation is based on public keycryptography and is more so-phisticated in its deployment. Au-tokey verifies both packet integrityand packet source using digitalsignatures. The S300 supportsAutokey as a server and/or aclient.

Time Reference SecurityThe best way to assure the correct timeis to have multiple, trusted timesources. The standard S300 supportssatellite based GPS, dial-up modemaccess to national time sources suchas NIST/ACTS, JJY, ITU-R TF583.4 andnetwork peering to trusted time servers.The NTP daemon continuously evaluatesall configured time sources and rejectsoutliers. In addition, the optional AM

radio for the S300 synchronizes to thegovernment maintained radio timebroadcasts available across the U.S.,Europe and Japan.

BEST PRACT ICES

• Always change the factory set password. Use RADIUS au-thentication if available.

• Keep the management port IP ad-dress private or exclusive. Use thethree other ports to serve time tothe network at large.

• Use access control lists onone or more ports to blockunauthorized IP addresses.

• Lockout front panel keypad accessto prevent unauthorized changes.

7

The Multiport configuration of the S300 with manage-ment on LAN 1 only is an excellent security measureand time distribution strategy.

Page 8: SyncServer S300 - marubun.co.jp€¦ · redundancy and versatility in network time servers, the SyncServer ® S300 GPS Network ... KEY BENEFITS • Synchronize ... Speed Network Fault

©2010 Symmetricom. Symmetricom and the Symmetricom logo are registered trademarks of Symmetricom, Inc. All specifications subject tochange without notice. DS/SSS300/122010/PDF

SYMMETRICOM, INC.

2300 Orchard ParkwaySan Jose, California 95131-1017tel: 408.433.0910fax: [email protected]

SyncServer S300 SPECIFICATIONS

NETWORK PROTOCOLSNTP (v2 - RFC1119, v3 - RFC1305, v4 -RFC5905)NTP Unicast, Broadcast, Multicast, Autokey SNTP Simple Network Time Protocol(RFC4330)

TIME (RFC868)

DAYTIME (RFC867)

HTTP/SSL/HTTPS (RFC2616)

SSH/SCP (Internet Draft)

Syslog 1 to 8 servers

Key management protocols can be individually disabled.

LAN 1: Management & Time protocols; LAN 2, 3 & GbE: Time protocols only.

SERVER PERFORMANCE• 7000 NTP requests per second while maintaining accuracy associated with reference

time source. The accuracy is inclusive of all NTP packet delays in and out of theSyncServer as measured at the network interface. Client synchronization accuracyto server on a LAN is 0.5 - 2 milliseconds (typical). The SyncServer easily supportsmany hundreds of thousands of NTP clients. NTP request handling capacityremains the same regardless of Stratum level.

• Stratum 1 via GPS: Overall time stamp accuracy of 7 microseconds to UTC with avariation of less than 42 microseconds typical

• Stratum 1 via Dial-up modem: <50 milliseconds to UTC (<20 ms typical).

• Stratum 2: Peering can be used as the primary mode of operation or as a back upmode in case the primary reference signals are lost. Time stamp accuracydepends on NTP peer server(s).

• Holdover Accuracy

TCXO (standard): 18 milliseconds/dayOCXO (optional): 1 milliseconds/dayRubidium (optional): 6 microseconds/day

GPS RECEIVER/ANTENNA• 12 channel parallel receiver

• Minimum number of satellites for time: 1 intermittently

• GPS time traceable to UTC (USNO)

• Accuracy: <50 ns RMS, 150 ns peak to peak to UTC, ≥4 satellites tracked.

• Maximum Belden 9104 cable length: 150' (45 m). For longer cable runs see Options.

INTERNAL ANALOG MODEM• Telecom approved in more than 50 countries

• Time Encoding: ACTS, JJY, and ITU-R TF583.4

MECHANICAL/ENVIRONMENTAL• Size: 1.75" x 17" x 11.25"

(4.5 cm x 43.2 cm x 28.6 cm) 1U rack mount

• Power: 100-240 VAC, 50-60 Hz, 25 watts(45 watts with Rb osc.),

• Operating temperature: 0°C to +50°C

• Storage temperature: -10°C to +70°C

• Humidity: To 95%, noncondensing

• Certifications: FCC, CE (RoHS), UL, PSE, China RoHS

• Server weight: 9 lbs (4.1 kgs), Shipping package: 16 lbs (7.3 kgs)

Front PanelDisplay: Sharp, high-resolution 32x256 dot-matrix

vacuum-fluorescent. 1, 2 or 4 line.

Keypad: 0-9 numeric, up, down, left, right, ENTER, CLR,TIME, STATUS, MENU. Keypad lockout.

LEDs (tri-color green/red/orange)

Sync: Time reference status

Network: Network connection status

NTP: NTP activity

Alarm: Fault condition

Serial: DB9-F 9600, N, 8, 1

USB: (2x) ports for back up, restore, and upgrade operations via the front panel.

Rear PanelNetwork (4x): 1x RJ-45 10Base-T/100Base-TX/1000Base-T

Gigabit Ethernet3x RJ-45 10Base-T/100Base-TX EthernetSpeed/Duplex: Auto, 10/full/half, 100/full/half

Sysplex: DB9-M RS-232

GPS: BNC L1, 1575 MHz

Modem: RJ-11 analog phone jack

Radio: BNC, Optional antenna required for operation.

Power: IEC 60320 C14 connector & power switch.

Relays: 2x, SPDT (Form C).

CLIENT SOFTWAREIncluded with the S300 is Symmetricom’s SymmTime NTP client for Windows. SeeOptions for comprehensive software solutions.

PRODUCT INCLUDESS300 Network Time Server, L1 GPS antenna, 50' (15 m) Belden 9104 coaxial cable,1 ft. antenna mounting mast (30 cm) with two clamps, category 5 patch cable, DB9-Mto DB9-F RS-232 extension cable, manual, SymmTime NTP client for Windows, En-terprise MIB software, power cord, and rack mount ear kit. Two-year warranty.

OPTIONS(To see Options datasheet please click here)

• Rubidium or OCXO oscillator upgrade for extended holdover

• AM Radio/Antenna (40, 60 or 77.5 kHz) for WWVB (USA), JJY (Japan) or DCF77 (Europe)

• ±40-60 Vdc power supply

• Window mounted GPS antenna

• GPS antenna in-line amplifier for cable runs to 300' (90 m)

• GPS antenna down/up converter for cable runs to 1500' (457 m)

• Lightning arrestor

• Comprehensive time client, server & management software for easy distribution,management and monitoring of time across the network.

• NTP Network Time Displays, 2” or 4” (5 cm or 10 cm), 6 digit, red LEDs

• IEEE 1588 / PTP Grandmaster option

Front View

Rear View

SNMP v1, v2c, v3 (RFC3584)Custom MIBDHCP (RFC2131)Telnet (RFC854)MD5 Authentication (RFC1321)RADIUS (RFC2865)SMTP ForwardingIPv4, IPv6 and IPv4/IPv6 Hybrid