Routelearn.net
Course menu

Course 12: IP Services on IOSLesson 1.1 (1 of 5 in this course)74 of 91 in the CCNA series

NTP configuration

Setting the clock and time zone, NTP client, server and peer modes, authentication, and verification.

Intermediate · 9 min read

NTP (Network Time Protocol) is a protocol that synchronises device clocks over a network using UDP port 123. A client measures the round-trip delay of its exchanges with a time server to correct its clock, and each server's stratum shows how many steps it is from a reference clock.

In simple terms: NTP keeps every device's clock showing the same time. That way log messages from different devices line up and can be compared.

A real-life situation

At 02:14 a link between R1 and R2 flapped and users lost the file server for a few seconds. You open the logs. R1 says the link went down at 09:47 on 1 March 1993. R2 says 02:15 today. SRV1 has its own idea. You can't line the events up, so you can't tell what failed first. Every Cisco device has its own clock, and unless something keeps them in step they drift apart or start from a default date after a reload.

The fix is the Network Time Protocol (NTP). The idea of NTP is covered in NTP: keeping time. This lesson is about configuring and checking it on Cisco IOS.

What NTP is

NTP lets a device ask another device for the time, measure how long the question took to travel, and correct its own clock. It runs over UDP port 123. On a Cisco device it can play three roles:

  • Client: takes time from a server (ntp server). It never gives time back to that server.
  • Server: gives time to others. A Cisco device that is synchronised automatically answers NTP clients; you don't need an extra command. ntp master makes it a server even with no outside source.
  • Symmetric peer: two devices that can correct each other (ntp peer).

Stratum is the distance from a real reference clock, such as a GPS receiver or an atomic clock. The reference clock itself is stratum 0. A server wired to it is stratum 1. A device that learns time from a stratum 1 server is stratum 2, and so on. A lower stratum means closer to the source. Stratum 16 means "not synchronised".

Reference clock (GPS)
Stratum 0
Public time server
Stratum 1 (time source for 198.51.100.10)
Internet
198.51.100.10 is stratum 2
R1 router
Client of 198.51.100.10, so stratum 3
R2 router and SW1 switch
Clients of R1, so stratum 4
Each hop away from the reference clock adds one to the stratum.

Why it works that way

Time can't be copied like a file, because the answer is already old when it arrives. NTP solves this by recording four timestamps for each exchange: when the client sent the request, when the server received it, when the server replied, and when the client got the reply. From these the client works out the delay (time on the wire) and the offset (how far its own clock is wrong). It then adjusts its clock gradually instead of jumping, so logs don't suddenly go backwards.

Stratum exists so devices can avoid loops and choose wisely. A client with several servers prefers the one with the lowest stratum and the most stable answers. A device won't take time from a source with a higher stratum than its own.

How it works step by step

In the lab, R1 takes time from an internet server and shares it with R2 and SW1.

Gi0/2 .2.1Gi0/0 .1192.168.10.0/24Gi0/1 .1.2 Gi0/010.0.12.0/30Gi0/1 .1192.168.20.0/24InternetNTP 198.51.100.10R1HQ edgeSW1mgmt 192.168.10.2PC1VLAN 10, DHCP clientR2server siteSRV1192.168.20.10
  1. 1. R1 asks the internet server. R1 is configured with ntp server 198.51.100.10 and sends a client request every poll interval (64 seconds at first).
  2. 2. The server answers. R1 calculates delay and offset, slowly corrects its clock and becomes stratum 3.
  3. 3. R2 asks R1. R2 is configured with ntp server 10.0.12.1. Because R1 is synchronised, it answers.
  4. 4. SW1 asks R1 too. SW1 uses ntp server 192.168.10.1. Both become stratum 4, and all log timestamps now agree.
Step 1 of 2 · Client request
R2 (client)
10.0.12.2
R1–R2 link
10.0.12.0/30
R1 (server)
10.0.12.1
R2 after a few exchanges
Stratum:
4
Reference:
10.0.12.1
Clock:
Synchronised
One NTP client/server exchange. Real clients repeat it every poll interval and filter the results.

How to configure it on Cisco IOS

1. Time zone and a manual starting point

NTP always carries UTC. The time zone only changes how the device shows the time. Setting the clock by hand first gets it close, so NTP doesn't have a huge gap to close.

clock timezone CET 1 0 clock summer-time CEST recurring last Sun Mar 2:00 last Sun Oct 3:00

Global configuration. The name is just a label; the numbers are the hours and minutes from UTC. summer-time is optional.

clock set 14:05:00 6 October 2026

Privileged EXEC, not configuration mode. Sets the software clock by hand.

ntp update-calendar

Optional, on routers with a hardware clock (the calendar): copy NTP time into it so the clock survives a reload.

2. R1 as client of the internet server

ntp server 198.51.100.10 prefer ntp server 203.0.113.1

Global configuration on R1. Two sources are better than one; prefer chooses which one wins when both are equally good.

3. R2 and SW1 as clients of R1

ntp server 10.0.12.1

On R2. Use an address that R2 can reach, and that stays up.

ntp server 192.168.10.1

On SW1. The switch needs a management IP (interface Vlan10) and a default gateway to reach it.

R1 needs no extra command to serve them. Once it is synchronised, it answers NTP requests.

4. Other modes

ntp master 4

Make this device an authoritative source from its own clock, at stratum 4 (default 8). For labs or isolated networks only.

ntp peer 10.0.12.2

Symmetric mode: R1 and R2 can correct each other. Usually configured on two devices at the same level that also have outside sources.

ntp source GigabitEthernet0/1

Send NTP from this interface's address. Useful when the far end only accepts known addresses, or when you use a loopback.

5. Authentication

Without authentication, a client believes any device that answers from the server address. NTP authentication adds a hash made with a shared secret key. The client checks it before using the time.

ntp authenticate ntp authentication-key 1 md5 Ntp-Lab-Key ntp trusted-key 1 ntp server 10.0.12.1 key 1

On the client (R2). ntp authenticate turns checking on; the key must also be listed as trusted and attached to the server.

ntp authentication-key 1 md5 Ntp-Lab-Key ntp trusted-key 1

On the server (R1). The key number and the key text must match exactly.

⚠️ Commands are based on Cisco IOS / IOS XE documentation and haven't been run in a lab here. Newer releases also accept stronger key types (for example hmac-sha2-256); MD5 is what the CCNA uses.

Full example

! R1 clock timezone CET 1 0 ntp authentication-key 1 md5 Ntp-Lab-Key ntp trusted-key 1 ntp server 198.51.100.10 prefer ntp server 203.0.113.1 ntp update-calendar ! ! R2 clock timezone CET 1 0 ntp authenticate ntp authentication-key 1 md5 Ntp-Lab-Key ntp trusted-key 1 ntp server 10.0.12.1 key 1 ! ! SW1 clock timezone CET 1 0 ntp server 192.168.10.1

How to verify it

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ntp associations
  address         ref clock       st   when   poll reach  delay  offset   disp
*~198.51.100.10   192.0.2.123      2     33     64   377 14.210  -0.612   1.937
+~203.0.113.1     198.51.100.10    3     51     64   377  2.105   0.144   1.802
 * sys.peer, # selected, + candidate, - outlyer, x falseticker, ~ configured
* marks the server R1 is actually synchronised to (sys.peer); + is a good backup; ~ means it was configured by hand. st is the server's stratum. reach 377 (octal) means the last eight polls all got answers. A reach of 0 means nothing is coming back.
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ntp status
Clock is synchronized, stratum 3, reference is 198.51.100.10
nominal freq is 250.0000 Hz, actual freq is 250.0003 Hz, precision is 2**10
...
clock offset is -0.6120 msec, root delay is 14.21 msec
...
Clock is synchronized and the stratum (one more than the server's) are the lines to check first.
Example output · based on Cisco documentation; exact format varies by platform and software version
R2#show clock detail
14:06:10.512 CET Tue Oct 6 2026
Time source is NTP
No symbol before the time means the clock is synchronised. An * would mean it isn't authoritative yet.

What goes wrong and how to troubleshoot it

  • Reach stays at 0. No replies arrive. Ping the server, check routing in both directions, and check that no ACL blocks UDP 123.
  • The server is listed but never gets a *. It can take several minutes to synchronise; NTP needs a few good samples first. If it never happens, the server itself may be unsynchronised (stratum 16) or the offset is huge. Set the clock close by hand with clock set and wait.
  • Works without authentication, fails with it. The key number or text differs, ntp trusted-key is missing, or key 1 was left off the ntp server line.
  • Time is right but shown wrong. The time zone offset is wrong, or summer time is missing. NTP itself is fine.
debug ntp packets

Shows NTP packets being sent and received. Turn it off with undebug all.

Common mistakes

  • Typing clock set in configuration mode. It is a privileged EXEC command.
  • Expecting ntp server to make the device a server. It makes it a client of that address.
  • Using ntp master on a router that also has a good outside source, which can hand out a less accurate time.
  • Turning on ntp authenticate on the server only. The command makes the device check the time it receives, so it belongs on the client.
  • Thinking the time zone is sent by NTP. Configure clock timezone on every device.

💡 Exam tip: know the difference between ntp server (client mode), ntp peer (symmetric) and ntp master (own clock, default stratum 8). Expect to read show ntp associations: find the * line and its stratum, and add one to get the local stratum. Remember UDP 123, and that clock set is an EXEC command.

Key takeaways

  • NTP keeps device clocks in step so logs, certificates and authentication work. It uses UDP 123 and carries UTC.
  • Stratum is the hop count from a reference clock; a client is one higher than its server.
  • ntp server = client mode, ntp peer = symmetric mode, ntp master = serve from the local clock.
  • Authentication needs ntp authenticate, a key, ntp trusted-key and key on the server line.
  • Verify with show ntp associations, show ntp status and show clock detail.

Accurate time matters most for logs: see SNMP and Syslog configuration.

Check yourself

Predict · scenario 1

R2 has 'ntp server 10.0.12.1'. show ntp associations on R2 shows '*~10.0.12.1' with st 3. What is R2's stratum?

Predict · scenario 2

A lab has no internet access. You want R1 to give time to every other device. Which command on R1 does that?

Predict · scenario 3

show ntp associations shows the configured server with reach 0. What is the most likely problem?

Predict · scenario 4

You enable authentication on R2 (the client) with ntp authenticate, the key and ntp trusted-key 1, but forget 'key 1' on the ntp server line. What happens?

Predict · scenario 5

Where do you type 'clock set 09:00:00 6 October 2026'?

FAQ

What is the difference between ntp server and ntp peer on Cisco IOS?
ntp server makes this device a client of the other one: it takes time from it but never gives time back. ntp peer creates a symmetric relationship: both devices can synchronise each other, and the better one wins. Peers are normally two devices at the same level, such as two core routers that each also use an outside source.
What does ntp master do?
It makes the router an authoritative NTP source using its own internal clock, at stratum 8 unless you give another number. Use it only when there is no better source, for example in an isolated lab. The clock is only as accurate as the time you set by hand.
Why does show clock have an asterisk in front of the time?
The asterisk means the time is not authoritative: the device has not been synchronised to NTP and the clock was never set reliably. A dot in front means the clock was set but is not currently synchronised. No symbol means it is synchronised.
Which port does NTP use?
UDP port 123, both as source and destination port between two NTP devices. If an ACL or firewall blocks UDP 123, NTP never synchronises.