Configuring NTP over Management VRF on an NTP Server

To implement NTP over Management VRF, a Network Time Protocol (NTP) server device must be configured to communicate with NTP client devices.
A Virtual Routing and Forwarding (VRF) instance named MGMT must be configured.
NTP over Management VRF allows NTP traffic to be isolated from network traffic. In the following figure, an NTP server is configured to run NTP over Management VRF with just one client and running over Virtual Ethernet (VE) interfaces.

After configuring the NTP server, configure the NTP client devices.

  1. Enter global configuration mode.
    device# configure terminal
  2. Configure a port-based VLAN and enter VLAN configuration mode.
    device(config)# vlan 20 by port
  3. Add an untagged port to the VLAN.
    device(config-vlan-20)# untagged ethernet 2/1/47
  4. Create a virtual routing interface.
    device(config-vlan-20)# interface ve 20
  5. Exit to global configuration mode.
    device(config-vlan-20)# exit
  6. Configure the VRF named management as a global management VRF.
    device(config)# management vrf MGMT strict
  7. Enter virtual interface mode for interface ve 20.
    device(config)# interface ve 20
  8. Configure the VRF named management as a forwarding VRF.
    device(config-if-ve-20)# vrf forwarding MGMT
  9. Configure an IP address on the interface.
    device(config-if-ve-20)# ip address 10.10.10.1 255.255.255.0
  10. Exit to global configuration mode.
    device(config-if-ve-20)# exit
  11. Enable the Network Time Protocol (NTP) client and server mode.
    device(config)# ntp
  12. Configure the device as an NTP master clock to which peers synchronize themselves when an external NTP source is not available.
    device(config-ntp)# master

The following example configures NTP over Management VRF on an NTP server, including the initial VRF configuration.

configure terminal
 vrf MGMT
  rd 3:3
  address-family ipv4
   ip route 0.0.0.0/0 10.10.10.1
    vlan 20 by port
  untagged ethernet 2/1/47 
  interface ve 20
  exit
 management vrf MGMT strict
 interface ve 20
  vrf forwarding MGMT
  ip address 10.10.10.1 255.255.255.0
  exit
 ntp
  master