Solved

NTP not updating

Posted on 2007-11-14
5
19,752 Views
Last Modified: 2013-12-12
Hello all,
I have a cisco router with a public IP and i want it to server as an NTP server on my network
I have configured NTP on my cisco router but it looks like it's not updating so i need some help

//I have the following to tell my router to broadcast NTP on GE0/1 that is connected to my LAN
interface GigabitEthernet0/1
 description gate1-Abj-ge-0-2
 ip address 192.168.115.101 255.255.255.252
 duplex auto
 speed auto
 media-type rj45
 negotiation auto
 ntp broadcast

//I have the following for NTP configuration
ntp source GigabitEthernet0/2 --This is the interface connected to internet with a public IP
ntp master
ntp server 128.9.176.30
ntp server 66.102.105.230
ntp server 83.67.145.167

//The clock is not sync
afnet1-Abj#sho ntp associations

      address         ref clock     st  when  poll reach  delay  offset    disp
*~127.127.7.1      127.127.7.1       7    48    64  377     0.0    0.00     0.0
 ~128.9.176.30     0.0.0.0          16  2374  1024    0     0.0    0.00  16000.
 ~66.102.105.230   0.0.0.0          16   426  1024    0     0.0    0.00  16000.
 ~83.67.145.167    0.0.0.0          16     -  1024    0     0.0    0.00  16000.
 * master (synced), # master (unsynced), + selected, - candidate, ~ configured
afnet1-Abj#sho
afnet1-Abj#show ntp st
afnet1-Abj#show ntp status
Clock is synchronized, stratum 8, reference is 127.127.7.1
nominal freq is 250.0000 Hz, actual freq is 249.9871 Hz, precision is 2**18
reference time is BDF6A082.6CC0E28B (05:32:50.424 UTC Fri Dec 29 2000)
clock offset is 0.0000 msec, root delay is 0.00 msec
root dispersion is 0.02 msec, peer dispersion is 0.02 msec
afnet1-Abj#sho clock
05:33:57.896 UTC Fri Dec 29 2000

I don't know what's wrong with my configuration
How can i check that the public NTP server i'm using is correctly broadcasting time ?
Can i force my router to update the clock to see if it's working ?

Thanks
0
Comment
Question by:lemaitre75
5 Comments
 
LVL 28

Accepted Solution

by:
Jan Springer earned 500 total points
ID: 20281045
The first thing I'd do is prevent it from using localhost net:

access-list 10 permit 128.9.176.30
access-list 10 permit  66.102.105.230
access-list 10  83.67.145.167

ntp access-group peer 10
ntp server 128.9.176.30 prefer
ntp server 66.102.105.230
ntp server 83.67.145.167

And look for access lists on the equipment blocking ntp port 123 incoming and outgoing.
0
 
LVL 10

Expert Comment

by:cstosgale
ID: 20281388
It looks like the router is synchronised to itself as an ntp server. First, I would remove the ntp master command, as this is making the router its own primary ntp server. In addition, it tends to help to put the source interface in the ntp server command. i.e.:-

no ntp master
ntp server 128.9.176.30 source GigabitEthernet0/2 prefer
ntp server 66.102.105.230 source GigabitEthernet0/2
ntp server 83.67.145.167 source GigabitEthernet0/2
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 20304299
>UTC Fri Dec 29 2000
You should try manually setting the current time/date on the router first. If it is too far off of the actual time, it won't sync up.

0
 

Author Comment

by:lemaitre75
ID: 20305819
this is the new configuration and it's working

ntp clock-period 17180766
ntp source GigabitEthernet0/2
ntp access-group peer 22 (as recommended by jesper)
ntp access-group serve-only 21 (i used this to restrict my internal ip that can use the router as an ntp server)
ntp master (i need this bcos it's my network ntp server)
ntp server 128.9.176.30 prefer
ntp server 66.102.105.230
ntp server 83.67.145.167

thanks
0
 
LVL 28

Expert Comment

by:Jan Springer
ID: 20306289
This looks good.  I've never used the 'ntp master' when using my router to sync externally and using the other equipment to sync off of that.

From priv prompt (but _not_ config mode):

# clock set HH:MM:SS DD MMM YYYY

i.e.,

# clock set 21:16:30 17 Nov 2007

You need to be within a minute or two of the actual clock for your clock to sync.
0

Featured Post

What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Routing VLANs 5 46
pfSense IP Helper 4 89
Monitor bandwidth 3 44
Network Config 9 57
This article is a guide to configure bridging on Cisco Routers.  This is something I never knew was possible until after making a few phone calls to Cisco.  Using bridging saved our company money by not requiring us to purchase a new switch.  Bridgi…
In the world of WAN, QoS is a pretty important topic for most, if not all, networks. Some WAN technologies have QoS mechanisms built in, but others, such as some L2 WAN's, don't have QoS control in the provider cloud.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now