Routelearn.net
Course menu

Unit 7: TCP, UDP and PortsLesson 7.3.6 (18 of 20 in this unit)51 of 84 in the Network Fundamentals course

NTP: keeping time

Why every device needs the same clock, and how NTP strata and servers work.

Intermediate · 6 min read

NTP (Network Time Protocol) is a protocol that synchronises the clocks of network devices with accurate time sources over UDP port 123. Time sources are ranked by stratum: their distance, in NTP hops, from a reference clock.

In simple terms: NTP keeps every device’s clock showing the same correct time. That way, you can line up logs from different devices to see what happened first.

A situation

Users reported an outage at 10:15. You open the logs of three routers. One says the link went down at 10:15, one says 09:52, and one says 1 March 1993, because its clock was reset when it rebooted. You cannot tell what happened first. Logs are only useful if every device agrees on the time.

What it is

NTP (Network Time Protocol) keeps device clocks in sync, usually to within a few milliseconds. It uses UDP port 123. A device that asks for the time is an NTP client; a device that gives it out is an NTP server. A router is often both: a client of a more accurate clock and a server for the switches below it.

Accurate time matters for more than logs. Certificates have start and end dates, so a wrong clock can break HTTPS and VPNs. Many security and authentication systems also reject requests from devices whose clock is wrong.

Strata: distance from the real clock

NTP describes how far a clock is from a very accurate source with a number called the stratum. An atomic clock or GPS receiver is stratum 0. A server connected directly to it is stratum 1. Each NTP hop adds one. A lower stratum is better, and 16 means “not synchronised”.

GPS clockstratum 0Time server192.0.2.10 · stratum 1R1stratum 2Core switchstratum 3PCsstratum 4
  1. 1. Stratum 1: the time server reads its GPS clock directly.
  2. 2. Stratum 2: R1 polls the time server and sets its own clock.
  3. 3. Stratum 3: the core switch uses R1 as its server, so it is one step further away.
  4. 4. Stratum 4: PCs synchronise with the core switch. Every device now agrees on the time.

Why it works this way

If every device asked one public server, that server would be overloaded and every request would cross the internet. A hierarchy spreads the load: only a few devices talk to outside servers, and the rest synchronise locally. NTP also measures the round-trip delay of each request and corrects for it (assuming the delay is the same in both directions), so time spent crossing the network does not make the clock wrong.

RoleCisco commandWhat it does
Clientntp server 192.0.2.10Synchronise this device with that server
Server(automatic)Once synchronised, the device answers NTP clients itself
Master (own clock)ntp master 4Trust the local clock as a source, at stratum 4. Used in labs and isolated networks

Configure it

These commands are based on Cisco documentation, not run on a lab device.

ntp server 192.0.2.10 prefer

On R1: use the stratum 1 server, and prefer it if more than one server is configured.

ntp server 10.1.1.1

On the core switch: use R1 (its LAN address) as the time source.

clock timezone CET 1 0

Optional: show local time. NTP itself always works in UTC (Coordinated Universal Time).

service timestamps log datetime msec localtime show-timezone

Add the date and time to each log message, so the synchronised clocks are useful in the logs.

How to verify it

These outputs are based on Cisco documentation, not run on a lab device.

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ntp status
Clock is synchronized, stratum 2, reference is 192.0.2.10
nominal freq is 250.0000 Hz, actual freq is 250.0003 Hz, precision is 2**10
ntp uptime is 1523000 (1/100 of seconds), resolution is 4000
reference time is EE6DF743.1C28F5C3 (10:15:31.110 UTC Mon Oct 5 2026)
clock offset is 0.5121 msec, root delay is 12.31 msec
root dispersion is 20.44 msec, peer dispersion is 1.03 msec
loopfilter state is 'CTRL' (Normal Controlled Loop), drift is -0.000001241 s/s
system poll interval is 64, last update was 33 sec ago.
What to look for: Clock is synchronized, stratum 2, reference is 192.0.2.10 is the line that matters. R1 is synchronised with the stratum 1 server. clock offset is 0.5121 msec shows that R1's clock is only about half a millisecond away from the server's time.
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ntp associations
  address         ref clock       st   when   poll reach  delay  offset   disp
*~192.0.2.10      .GPS.            1     33     64   377 12.310   0.512  1.030
 * sys.peer, # selected, + candidate, - outlyer, x falseticker, ~ configured
What to look for: the * marks the server R1 is synchronised with, and .GPS. is that server's own reference clock. st 1 is the server's stratum. A reach of 377 (octal for eight successes in a row) means the last eight polls all got answers.

Check yourself

Predict · scenario 1

A switch synchronises its clock with a router that is at stratum 3. What stratum does the switch become?

Predict · scenario 2

After you configure ntp server on a router, show ntp status says "Clock is unsynchronized, stratum 16". What does that mean?

Predict · scenario 3

A firewall sits between R1 and its time server. Which transport and port must the firewall allow for NTP?