Configuring NTP over Management VRF on an NTP Client

To implement NTP over Management VRF, a Network Time Protocol (NTP) client device must be configured to communicate with an NTP server device.
A Virtual Routing and Forwarding (VRF) instance named MGMT must be configured.
NTP over Management VRF allows NTP traffic to be isolated from network traffic. In the following figure, an NTP client is configured to run NTP over Management VRF and communicate with an NTP server device. Be sure to use the appropriate interface modifications on all other NTP clients that are to communicate with the NTP server.

  1. Enter global configuration mode.
    device# configure terminal
  2. Configure a port-based VLAN and enter VLAN configuration mode.
    device(config)# vlan 20 by port
  3. Add an untagged port to the VLAN.
    device(config-vlan-20)# untagged ethernet 1/2/1
  4. Create a virtual routing interface.
    device(config-vlan-20)# interface ve 20
  5. Exit to global configuration mode.
    device(config-vlan-20)# exit
  6. Configure the VRF named management as a global management VRF.
    device(config)# management vrf mgmt strict
  7. Enter virtual interface mode for interface ve 20.
    device(config)# interface ve 20
  8. Configure the VRF named mgmt as a forwarding VRF.
    device(config-if-ve-20)# vrf forwarding mgmt
  9. Configure an IP address on the interface.
    device(config-if-ve-20)# ip address 10.10.10.2 255.255.255.0
  10. Exit to global configuration mode.
    device(config-if-ve-20)# end
  11. Identify the source interface for the NTP server.
    device# configure terminal
    device(config)# management source-interface ve 20 protocol ntp 
  12. Enable the Network Time Protocol (NTP) client and server mode.
    device(config)# ntp
  13. Identify the IP address of the VE interface through which the management VRF is running.
    device(config-ntp)# server 10.10.10.1

The following example configures NTP over Management VRF on an NTP Client including the initial VRF configuration.

configure terminal
 vrf mgmt
  rd 3:3
  address-family ipv4
   ip route 0.0.0.0/0 10.10.10.2
   vlan 20 by port
  untagged ethernet 1/2/1
  interface ve 20
  exit
 management vrf mgmt strict
 interface ve 20
  vrf forwarding mgmt
  ip address 10.10.10.2 255.255.255.0
management source-interface ve 20 protocol ntp 
 ntp  
  server 10.10.10.1