Configuring NTP
NTP services are disabled on all interfaces by default. To enable NTP in both NTP
client and server mode, enter the
ntp command in global configuration mode. This puts the device in NTP configuration sub-mode
as shown in the following example.
Device# configure terminal Device(conf)# ntp Device(conf-ntp)#
Syntax: [no] ntp
Use the
no form of the command if you need to disable NTP and remove the NTP configuration.
The
no ntp command removes all manual and statistical configuration as well as learned associations
from NTP neighbors.
By default, no NTP servers are configured. To configure the device in client mode
and specify the NTP servers to synchronize the system clock, use the
server command in NTP configuration sub-mode as shown in the following example.
A maximum of eight NTP servers can be configured. To remove NTP server configuration,
use the
no form of the
server command.
To configure communication to an NTP server forcing NTPv3, enter commands similar to those shown in the following example.
Device# configure terminal Device(config)# ntp Device(config-ntp)# server 129.6.15.30 version 3 key 1
The server command in the previous example tells the RUCKUS device to use NTPv3 to communicate with the server
with the IP address 129.6.15.30.
The following example configures an NTP version 4 server with the IP address 129.6.15.30. The parameter key is followed by the authentication key ID 5 in the example. An example of defining an authentication key is provided at the end of this section. The configuration generates syslog messages similar to those shown.
Device(config)# ntp Device(config-ntp)# server 129.6.15.30 version 4 key 5 SYSLOG: <14> May 14 10:01:18 Device NTP: client association is mobilized for 129.6.15.30. SYSLOG: <14> May 14 10:01:18 Device NTP: The system clock is not synchronized to any time source.
As soon as the system time is synchronized with the server, the following syslog messages are displayed.
SYSLOG: <14> May 14 10:50:54 Device Security: Time is updated by NTP server "129.6.15.30" from "10:02:55.830 Pacific Thu May 14 2020 " to "10:50:54.312 Pacific Thu May 14 2020 " SYSLOG: <14> May 14 10:51:37 Device NTP: Stratum is changed to 4. SYSLOG: <14> May 20 16:34:16 Device NTP: System clock is synchronized to 129.6.15.30.
Defining an authentication key
Define an authentication key to be used with the NTP server as shown in the following example. The allowable range for key IDs is 1 through 65535. The authentication key should use the same key ID value configured on the NTP server. The same key ID and key string should be installed on all NTP devices.
The sha1 keyed hash algorithm must be used for NTP authentication. Follow the sha1 parameter with a key string containing no more than 16 alphanumeric characters.
In an evaluated configuration the following actions are allowed:
- An administrator can set the time manually and NOT use NTP.
- An administrator can set the time and configure NTP to authenticate to multiple servers but ONLY using SHA1 message digest authentication.
If you must remove the authentication key, use the no form of the command.
Device(config)# ntp Device(config-ntp)# authentication-key key-id 5 sha1 pass1234
Enabling and disabling an ICX device as an NTP server
A RUCKUS ICX device can be used as an NTP client or server or both.
To enable NTP client mode only on an ICX device,
use the no disable
command.
To enable both NTP client and server
mode on the ICX device, use the no disable serve
command.
To disable both the NTP client and the NTP
server mode on the ICX device, use the disable command without
parameters in NTP configuration sub-mode.
To disable only the NTP server mode on the ICX
device, use the disable
serve command as shown in the following example. The disable
serve command disables NTP server mode functionalities on the ICX
device, and NTP does not serve the time to downstream devices.
Device(config)# ntp Device(config-ntp)# disable serve
Enabling NTP strict authentication
When authentication is enabled, NTP packets that do not have a valid MAC (message authentication code) are dropped. The following example enables NTP strict authentication.
Device(config)# ntp Device(config-ntp)# authenticate
Use the
no form of the command to disable NTP strict authentication.
NTP limitations
Consider the following limitations when configuring NTP on FastIron devices:
- A FastIron device cannot operate as the primary time server (Stratum 1). It can only serves as the secondary time server (Stratum 2 to 15).
- The NTP server and client cannot communicate using hostnames.
- NTP is not supported on VRF-enabled interfaces.
- Autokey public key authentication is not supported.
- The NTP version 4 extension fields are not supported. Any packets containing the extension fields are discarded.
- NTP packets in control (6) or private (7) packet mode are not supported. NTP packets with control and private modes are discarded.
- On reboot or switchover, all NTP state information is lost, and time synchronization starts fresh.
- A FastIron device rejects multicast, broadcast, and manycast server and client time updates from all NTP servers.
- Only NTP versions 3 and 4 are supported. (NTP versions 1 and 2 are not supported.)
- NTP MIB is not supported.