User Tools

Site Tools


tech:network:cisco:clock:clock

Cisco: Clock

Blueprint

  • CCIE R&S
    • Written v5.1
      • 6.0 Infrastructure Services
        • 6.1 System management
          • 6.1.c Implement and troubleshoot logging
          • 6.1.c [ii] Timestamp
      • 6.3 Network services
        • 6.3.b Implement and troubleshoot network time protocol
          • 6.3.b [i] NTP master, client, version 3, version 4
          • 6.3.b [ii] NTP Authentication
    • Lab v5.0
      • 5.0 Infrastructure Services
        • 5.1 System management
          • 5.1.c Implement and troubleshoot logging
            • 5.1.c [ii] Timestamp
        • 5.3 Network services
          • 5.3.b Implement and troubleshoot network time protocol
            • 5.3.b [i] NTP master, client, version 3, version 4
            • 5.3.b [ii] NTP authentication

Manual Configuration

configure terminal
!
clock timezone JST 9
!
end

Hardware clock seems not implemented in Catalyst 3750, 2960.

Cisco ISR 1841 Router has hardware clock.

Log

Daylight Saving Time(DST, Summer Time)

Japan is not use DST. So, following configuration is not practical example.

configure terminal
!
! recurring every year
clock summer-time JST recurring 4 Sun Sep 14:15 4 Sun Sep 17:00 105
!
! absolute time one shot summer time
clock summer-time JST date 22 Sep 2019 19:00 22 Sep 2019 22:00 120
!
end

Console Log

NTP

Server / Client Configuration

configure terminal
!
vtp mode transparent
!
vlan 128
exit
!
ip routing
!
spanning-tree portfast default
!
interface Vlan 128
 ip address 10.0.128.1 255.255.255.0
exit
!
interface FastEthernet 1/0/24
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 128
exit
!
end
configure terminal
!
clock timezone JST 9
!
ntp server 10.0.128.254 prefer
!
end
show ntp associations

Console Log

NTP Symmetric Active / Passive Mode

  • SW1
configure terminal
!
vtp mode transparent
!
vlan 128
exit
!
ip routing
!
interface Vlan 128
 ip address 10.0.128.1 255.255.255.0
exit
!
interface Loopback 0
 ip address 10.0.130.1 255.255.255.255
exit
interface FastEthernet 1/0/23
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 128
exit
interface FastEthernet 1/0/24
 no switchport
 ip address 10.0.129.1 255.255.255.0
exit
!
router ospf 1
 network 10.0.128.1 0.0.0.0 area 0
 network 10.0.129.1 0.0.0.0 area 0
 network 10.0.130.1 0.0.0.0 area 0
exit
!
end
  • SW2
configure terminal
!
vtp mode transparent
!
vlan 128
exit
!
ip routing
!
interface Vlan 128
 ip address 10.0.128.2 255.255.255.0
exit
!
interface Loopback 0
 ip address 10.0.131.2 255.255.255.255
exit
interface FastEthernet 1/0/23
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 128
exit
interface FastEthernet 1/0/24
 no switchport
 ip address 10.0.129.2 255.255.255.0
exit
!
router ospf 1
 network 10.0.128.2 0.0.0.0 area 0
 network 10.0.129.2 0.0.0.0 area 0
 network 10.0.131.2 0.0.0.0 area 0
exit
!
end
  • SW10
configure terminal
!
vtp mode transparent
!
vlan 128
exit
!
interface range FastEthernet 0/1 - 2
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 128
exit
interface GigabitEthernet 0/1
 spanning-tree portfast trunk
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 128
exit
!
end
  • SW1
configure terminal
!
clock timezone JST 9
!
ntp server 10.0.128.254
!
ntp peer 10.0.131.2 source Loopback 0 prefer
ntp master 7
!
end
  • SW2
configure terminal
!
clock timezone JST 9
!
ntp server 10.0.128.254
!
ntp peer 10.0.130.1 source Loopback 0 prefer
ntp master 7
!
end
configure terminal
!
no ntp server 10.0.128.254
!
end
show ntp associations
show ntp status

Console Log SW1

Console Log SW2

I can't understand this feature…

[Incomplete Lab] NTP Broadcast Mode

This Lab is incomplete because lack of feature Catalyst 3750…

  • SW1
configure terminal
!
vtp mode transparent
!
vlan 128
exit
vlan 129
exit
!
ip routing
!
interface Vlan 128
 ip address 10.0.128.1 255.255.255.0
exit
interface Vlan 129
 ip address 10.0.129.1 255.255.255.0
exit
!
interface range FastEthernet 1/0/1 - 3
 spanning-tree portfast
 switchport mode access
 switchport access vlan 129
exit
interface range FastEthernet 1/0/4 - 6
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 129
exit
interface FastEthernet 1/0/23
 spanning-tree portfast
 switchport mode access
 switchport access vlan 128
exit
interface FastEthernet 1/0/24
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 128
exit
!
end
  • SW2 - SW4
configure terminal
!
vtp mode transparent
!
vlan 129
exit
!
ip routing
!
interface Vlan 129
 ip address 10.0.129.2 255.255.255.0
exit
!
interface FastEthernet 1/0/1
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 129
exit
!
end
  • R1
configure terminal
!
interface FastEthernet 0/0
 ip address 10.0.129.11 255.255.255.0
 no shutdown
exit
interface FastEthernet 0/1
 ip address 10.0.128.11 255.255.255.0
 no shutdown
exit
!
end
  • R1 - R3
configure terminal
!
interface FastEthernet 0/0
 ip address 10.0.129.11 255.255.255.0
 no shutdown
exit
!
end
  • R1
configure terminal
!
clock timezone JST 9
!
ntp server 10.0.128.254
!
interface range FastEthernet 1/0/1 - 6
 ntp broadcast version 3
exit
!
end
  • R2, R3
configure terminal
!
clock timezone JST 9
!
int f0/0
 ntp broadcast client
!
end
show ntp associations
show ntp status

May be ntp broadcast is not supported in Catalyst 3750 w/ 15.0

I'll use router.

ntp broadcast packet not observed….

ntp version default to 4? ntp version mismatch?

NTP Broadcast Mode

This Lab uses Cisco ISR 1841. IOS 15.x

  • SW1
configure terminal
!
vtp mode transparent
!
vlan 128
exit
vlan 129
exit
!
ip routing
!
interface Vlan 128
 ip address 10.0.128.1 255.255.255.0
exit
interface Vlan 129
 ip address 10.0.129.1 255.255.255.0
exit
!
interface range FastEthernet 1/0/1 - 3
 spanning-tree portfast
 switchport mode access
 switchport access vlan 129
exit
interface FastEthernet 1/0/23
 spanning-tree portfast
 switchport mode access
 switchport access vlan 128
exit
interface FastEthernet 1/0/24
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 128
exit
!
end
  • R1
configure terminal
!
interface FastEthernet 0/0
 ip address 10.0.129.11 255.255.255.0
 no shutdown
exit
interface FastEthernet 0/1
 ip address 10.0.128.11 255.255.255.0
 no shutdown
exit
!
end
  • R2
configure terminal
!
interface FastEthernet 0/0
 ip address 10.0.129.12 255.255.255.0
 no shutdown
exit
!
end
  • R3
configure terminal
!
interface FastEthernet 0/0
 ip address 10.0.129.13 255.255.255.0
 no shutdown
exit
!
end
  • R1
configure terminal
!
clock timezone JST 9
!
ntp server 10.0.128.254
!
interface FastEthernet 0/0
 ntp broadcast version 3
exit
!
end
  • R2, R3
configure terminal
!
clock timezone JST 9
!
int f0/0
 ntp broadcast client
!
end
show ntp associations
show ntp status

May be ntp broadcast is not supported in Catalyst 3750 w/ 15.0

I'll use router.

ntp broadcast packet not observed….

ntp version default to 4? ntp version mismatch?

R1 Console Log

R2 Console Log

R3 Console Log

NTP Multicast Mode

Cisco IOS IPv6 Command Reference - mpls traffic-eng auto-bw timers through route-map [Support & Downloads] - Cisco

  • SW1
configure terminal
!
vtp mode transparent
!
vlan 128
exit
vlan 129
exit
!
ip routing
!
interface Vlan 128
 ip address 10.0.128.1 255.255.255.0
exit
interface Vlan 129
 ip address 10.0.129.1 255.255.255.0
exit
!
interface range FastEthernet 1/0/1 - 3
 spanning-tree portfast
 switchport mode access
 switchport access vlan 129
exit
interface range FastEthernet 1/0/4 - 6
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 129
exit
interface FastEthernet 1/0/23
 spanning-tree portfast
 switchport mode access
 switchport access vlan 128
exit
interface FastEthernet 1/0/24
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 128
exit
!
end
  • R1
ipv6 unicast-routing
!
ntp server 10.0.128.254
!
int f0/1
 ip address 10.0.128.11 255.255.255.0
 no shutdown
int f0/0
 ipv6 enable
 ipv6 address fe80::1 link-local
 ntp multicast version 4 ff02::1
  • R2
ipv6 unicast-routing
!
int f0/0
 ipv6 enable
 ipv6 address fe80::2 link-local
 ntp multicast client ff02::1
 no shutdown
  • R3
ipv6 unicast-routing
!
int f0/0
 ipv6 enable
 ipv6 address fe80::3 link-local
 ntp multicast client ff02::1
 no shutdown

Console Log

Authentication

  • SW1
configure terminal
!
vtp mode transparent
!
vlan 128
exit
vlan 129
exit
!
ip routing
!
interface Vlan 128
 ip address 10.0.128.1 255.255.255.0
exit
interface Vlan 129
 ip address 10.0.129.1 255.255.255.0
exit
!
interface range FastEthernet 1/0/1 - 3
 spanning-tree portfast
 switchport mode access
 switchport access vlan 129
exit
interface range FastEthernet 1/0/4 - 6
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 129
exit
interface FastEthernet 1/0/23
 spanning-tree portfast
 switchport mode access
 switchport access vlan 128
exit
interface FastEthernet 1/0/24
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 128
exit
!
end
  • SW2
configure terminal
!
vtp mode transparent
!
vlan 129
exit
!
ip routing
!
interface Vlan 129
 ip address 10.0.129.2 255.255.255.0
exit
!
interface FastEthernet 1/0/1
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 129
exit
!
end
  • SW1
configure terminal
!
ntp server 10.0.128.254
!ntp server 10.0.128.254 key 1
!
ntp authenticate
ntp authentication-key 1 md5 pg1x
ntp trusted-key 1
!
end
  • SW2
configure terminal
!
ntp authenticate
ntp authentication-key 1 md5 pg1x
ntp trusted-key 1
ntp server 10.0.129.1 key 1
!
end
  • SW4
monitor session 1 source interface Fa1/0/4
monitor session 1 destination interface Fa1/0/12 encapsulation replicate
/etc/chrony/chrony.conf
keyfile /etc/chrony/chrony.keys
/etc/chrony/chrony.keys
1 MD5 ASCII:pg1x

column 1 means ID, ID may be must same.

And config changed, you must restart chronyd.

sudo systemctl restart chronyd
sudo systemctl status chronyd

sometimes works fine, i reset ntp configuration and input over.

no ntp
clock timezone JST 9
clock set 00:00:00 3 Jan 2010
root@kozue:~# chronyc clients
Hostname                      NTP   Drop Int IntL Last     Cmd   Drop Int  Last
===============================================================================
10.0.128.1                      3      0   6   -    26       0      0   -     -

SW1 Console Log

SW2 Console Log

ACL

  • SW1
configure terminal
!
vtp mode transparent
!
vlan 128-130
exit
!
ip routing
!
interface Vlan 128
 ip address 10.0.128.1 255.255.255.0
exit
interface Vlan 129
 ip address 10.0.129.1 255.255.255.0
exit
interface Vlan 130
 ip address 10.0.130.1 255.255.255.0
exit
!
interface FastEthernet 1/0/21
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 128
exit
interface FastEthernet 1/0/23
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 129,130
exit
interface FastEthernet 1/0/24
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 129,130
exit
interface range FastEthernet 1/0/1 - 3
 spanning-tree portfast
 switchport mode access
 switchport access vlan 130
exit
!
end
  • SW2
configure terminal
!
vtp mode transparent
!
vlan 128-130
exit
!
ip routing
!
interface Vlan 128
 ip address 10.0.128.2 255.255.255.0
exit
interface Vlan 129
 ip address 10.0.129.2 255.255.255.0
exit
interface Vlan 130
 ip address 10.0.130.2 255.255.255.0
exit
!
interface FastEthernet 1/0/21
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 128
exit
interface FastEthernet 1/0/23
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 129,130
exit
interface FastEthernet 1/0/24
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 129,130
exit
interface range FastEthernet 1/0/1 - 3
 spanning-tree portfast
 switchport mode access
 switchport access vlan 130
exit
!
end
  • SW3
configure terminal
!
vtp mode transparent
!
vlan 128-130
exit
!
ip routing
!
interface Vlan 128
 ip address 10.0.128.3 255.255.255.0
exit
interface Vlan 129
 ip address 10.0.129.3 255.255.255.0
exit
interface Vlan 130
 ip address 10.0.130.3 255.255.255.0
exit
!
interface FastEthernet 1/0/21
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 128
exit
interface FastEthernet 1/0/23
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 129,130
exit
interface FastEthernet 1/0/24
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 129,130
exit
interface range FastEthernet 1/0/1 - 3
 spanning-tree portfast
 switchport mode access
 switchport access vlan 130
exit
!
end
  • SW4
configure terminal
!
vtp mode transparent
!
vlan 128-130
exit
!
ip routing
!
interface Vlan 128
 ip address 10.0.128.4 255.255.255.0
exit
interface Vlan 129
 ip address 10.0.129.4 255.255.255.0
exit
interface Vlan 130
 ip address 10.0.130.4 255.255.255.0
exit
!
interface FastEthernet 1/0/23
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 128
exit
interface FastEthernet 1/0/24
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk allowed vlan 129,130
exit
interface range FastEthernet 1/0/1 - 3
 spanning-tree portfast
 switchport mode access
 switchport access vlan 130
exit
!
end
  • SW10
configure terminal
!
vtp mode transparent
!
vlan 128
exit
!
ntp logging
clock timezone JST 9
ntp server 10.0.128.254
ntp server 10.0.128.1
ntp server 10.0.128.2
ntp server 10.0.128.3
ntp server 10.0.128.4
!
interface Vlan 128
 ip address 10.0.128.10 255.255.255.0
exit
!
interface range FastEthernet 0/1 - 8
 switchport mode trunk
 switchport trunk allowed vlan 128
exit
interface GigabitEthernet 0/1
 spanning-tree portfast trunk
 switchport mode trunk
 switchport trunk allowed vlan 128
exit
!
end
  • R1
clock set 00:00:00 1 Jan 2001
clock update-calendar
!
configure terminal
!
clock timezone JST 9
ntp logging
!
ntp server 10.0.128.254
ntp server 10.0.130.1
ntp server 10.0.130.2
ntp server 10.0.130.3
ntp server 10.0.130.4
!
interface range FastEthernet 0/0
 ip address 10.0.130.11 255.255.255.0
 no shutdown
exit
!
ip route 0.0.0.0 0.0.0.0 10.0.130.1
!
end
  • R2
clock set 00:00:00 1 Jan 2001
clock update-calendar
!
configure terminal
!
clock timezone JST 9
ntp logging
!
ntp server 10.0.128.254
ntp server 10.0.130.1
ntp server 10.0.130.2
ntp server 10.0.130.3
ntp server 10.0.130.4
!
interface range FastEthernet 0/0
 ip address 10.0.130.12 255.255.255.0
 no shutdown
exit
!
ip route 0.0.0.0 0.0.0.0 10.0.130.2
!
end
  • R3
clock set 00:00:00 1 Jan 2001
clock update-calendar
!
configure terminal
!
clock timezone JST 9
ntp logging
!
ntp server 10.0.128.254
ntp server 10.0.130.1
ntp server 10.0.130.2
ntp server 10.0.130.3
ntp server 10.0.130.4
!
interface range FastEthernet 0/0
 ip address 10.0.130.13 255.255.255.0
 no shutdown
exit
!
ip route 0.0.0.0 0.0.0.0 10.0.130.3
!
end
  • SW1
configure terminal
!
clock timezone JST 9
ntp logging
!
ntp server 10.0.128.254
!
ntp peer 10.0.129.2
ntp peer 10.0.129.3
ntp peer 10.0.129.4
ntp master 5
!
end
  • SW2
configure terminal
!
clock timezone JST 9
ntp logging
!
ntp server 10.0.128.254
!
ntp peer 10.0.129.1
ntp peer 10.0.129.3
ntp peer 10.0.129.4
ntp master 5
!
end
  • SW3
configure terminal
!
clock timezone JST 9
ntp logging
!
ntp server 10.0.128.254
!
ntp peer 10.0.129.1
ntp peer 10.0.129.2
ntp peer 10.0.129.4
ntp master 5
!
end
  • SW4
configure terminal
!
clock timezone JST 9
ntp logging
!
ntp server 10.0.128.254
!
ntp peer 10.0.129.1
ntp peer 10.0.129.2
ntp peer 10.0.129.3
ntp master 5
!
end
  • SW1
configure terminal
!
access-list 1 permit host 10.0.129.2
access-list 1 permit host 10.0.129.3
access-list 1 permit host 10.0.129.4
access-list 1 deny any log
access-list 2 permit host 10.0.130.11
access-list 2 permit host 10.0.130.12
access-list 2 permit host 10.0.130.13
access-list 2 deny any log
access-list 3 permit host 10.0.128.254
!
ntp access-group peer 1
ntp access-group serve-only 2
ntp access-group peer 3
!
end
do clock set 00:00:00 1 Jan 2001

not allowed peer or server increase when value.

Console Log

Disable NTP Interface

Catalyst 3750 not applicable this command.

  • R3
configure terminal
!
interface FastEthernet 0/0
 ntp disable
!
end

Console Log

Misc

configure terminal
!
ntp max-associations 3
!
end

Console Log

References

tech/network/cisco/clock/clock.txt · Last modified: 2019/09/29 16:58 by wnoguchi