Configuring NTP

NTP services are disabled on all interfaces by default. To enable NTP in both NTP client and server mode, enter the ntp command in global configuration mode. This puts the device in NTP configuration sub-mode as shown in the following example.

Device# configure terminal
Device(conf)# ntp
Device(conf-ntp)# 

Syntax: [no] ntp

Use the no form of the command if you need to disable NTP and remove the NTP configuration. The no ntp command removes all manual and statistical configuration as well as learned associations from NTP neighbors.

By default, no NTP servers are configured. To configure the device in client mode and specify the NTP servers to synchronize the system clock, use the server command in NTP configuration sub-mode as shown in the following example.

A maximum of eight NTP servers can be configured. To remove NTP server configuration, use the no form of the server command.

Note: Only NTP version 3 or NTP version 4 is supported. NTP version 4 is the default configuration.

To configure communication to an NTP server forcing NTPv3, enter commands similar to those shown in the following example.

Device# configure terminal
Device(config)# ntp
Device(config-ntp)# server 129.6.15.30 version 3 key 1

The server command in the previous example tells the RUCKUS device to use NTPv3 to communicate with the server with the IP address 129.6.15.30.

The following example configures an NTP version 4 server with the IP address 129.6.15.30. The parameter key is followed by the authentication key ID 5 in the example. An example of defining an authentication key is provided at the end of this section. The configuration generates syslog messages similar to those shown.

Device(config)# ntp
Device(config-ntp)# server 129.6.15.30 version 4 key 5

SYSLOG: <14> May 14 10:01:18 Device NTP: client association is mobilized for 129.6.15.30. 

SYSLOG: <14> May 14 10:01:18 Device NTP: The system clock is not synchronized to any time source. 

As soon as the system time is synchronized with the server, the following syslog messages are displayed.

SYSLOG: <14> May 14 10:50:54 Device Security: Time is updated by NTP server "129.6.15.30" from  "10:02:55.830 Pacific Thu May 14 2020 " to "10:50:54.312 Pacific Thu May 14 2020 " 

SYSLOG: <14> May 14 10:51:37 Device NTP: Stratum is changed to 4. 

SYSLOG: <14> May 20 16:34:16 Device NTP: System clock is synchronized to 129.6.15.30. 

Defining an authentication key

Define an authentication key to be used with the NTP server as shown in the following example. The allowable range for key IDs is 1 through 65535. The authentication key should use the same key ID value configured on the NTP server. The same key ID and key string should be installed on all NTP devices.

The sha1 keyed hash algorithm must be used for NTP authentication. Follow the sha1 parameter with a key string containing no more than 16 alphanumeric characters.

Note: You must use sha1. Other algorithms such as md5 are NOT supported.

In an evaluated configuration the following actions are allowed:

  1. An administrator can set the time manually and NOT use NTP.
  2. An administrator can set the time and configure NTP to authenticate to multiple servers but ONLY using SHA1 message digest authentication.

Note: An administrator CANNOT configure NTP without authentication of the NTP server using SHA1 message digest authentication.

If you must remove the authentication key, use the no form of the command.

Device(config)# ntp
Device(config-ntp)# authentication-key key-id 5 sha1 pass1234

Enabling and disabling an ICX device as an NTP server

A RUCKUS ICX device can be used as an NTP client or server or both.

To enable NTP client mode only on an ICX device, use the no disable command.

To enable both NTP client and server mode on the ICX device, use the no disable serve command.

To disable both the NTP client and the NTP server mode on the ICX device, use the disable command without parameters in NTP configuration sub-mode.

Note: The disable command disables NTP on the ICX device but does not remove related configuration.

To disable only the NTP server mode on the ICX device, use the disable serve command as shown in the following example. The disable serve command disables NTP server mode functionalities on the ICX device, and NTP does not serve the time to downstream devices.

Device(config)# ntp
Device(config-ntp)# disable serve

Enabling NTP strict authentication

When authentication is enabled, NTP packets that do not have a valid MAC (message authentication code) are dropped. The following example enables NTP strict authentication.

Device(config)# ntp
Device(config-ntp)# authenticate

Use the no form of the command to disable NTP strict authentication.

NTP limitations

Consider the following limitations when configuring NTP on FastIron devices:

  • A FastIron device cannot operate as the primary time server (Stratum 1). It can only serves as the secondary time server (Stratum 2 to 15).
  • The NTP server and client cannot communicate using hostnames.
  • NTP is not supported on VRF-enabled interfaces.
  • Autokey public key authentication is not supported.
  • The NTP version 4 extension fields are not supported. Any packets containing the extension fields are discarded.
  • NTP packets in control (6) or private (7) packet mode are not supported. NTP packets with control and private modes are discarded.
  • On reboot or switchover, all NTP state information is lost, and time synchronization starts fresh.
  • A FastIron device rejects multicast, broadcast, and manycast server and client time updates from all NTP servers.
  • Only NTP versions 3 and 4 are supported. (NTP versions 1 and 2 are not supported.)
  • NTP MIB is not supported.