Example: Configuring NTP


The Network Time Protocol (NTP) provides the mechanisms to synchronize time and coordinate time distribution in a large, diverse network. NTP uses a returnable-time design in which a distributed subnet of time servers operating in a self-organizing, hierarchical primary-secondary configuration synchronizes local clocks within the subnet and to national time standards by means of wire or radio. The servers also can redistribute reference time using local routing algorithms and time daemons.

This example shows how to configure NTP:


This example uses the following software and hardware components:

  • Junos OS Release 11.1 or later

  • A switch connected to a network on which an NTP boot server and NTP server reside


Debugging and troubleshooting are much easier when the timestamps in the log files of all switches are synchronized, because events that span a network can be correlated with synchronous entries in multiple logs. We recommend using the Network Time Protocol (NTP) to synchronize the system clocks of your switch and other network equipment.

In this example, an administrator wants to synchronize the time in a switch to a single time source. We recommend using authentication to make sure that the NTP peer is trusted. The boot-server statement identifies the server from which the initial time of day and date are obtained when the switch boots. The server statement identifies the NTP server used for periodic time synchronization. The authentication-key statement specifies that an HMAC-Message Digest 5 (MD5) scheme is used to hash the key value for authentication, which prevents the switch from synchronizing with an attacker’s host that is posing as the time server.


To configure NTP:

CLI Quick Configuration

To quickly configure NTP, copy the following commands and paste them into the switch’s terminal window:

[edit system]

set ntp boot-server

set ntp server

set ntp authentication-key 2 type md5 value "$ABC123"

Step-by-Step Procedure

To configure NTP :

  1. Specify the boot server:
    [edit system]

    user@switch# set ntp boot-server
  2. Specify the NTP server:
    [edit system]

    user@switch# set ntp server
  3. Specify the key number, authentication type (MD5), and key for authentication:
    [edit system]

    user@switch# set ntp authentication-key 2 type md5 value "$ABC123"


Check the results:


To confirm that the configuration is correct, perform these tasks:

Checking the Time


Check the time that has been set on the switch.


Enter the show system uptime operational mode command to display the time.

user@switch> show system uptime


The output shows that the current date and time are June 12, 2009 and 12:49:03 PDT. The switch booted 4 weeks, 6 hours, and 24 minutes ago, and its protocols were started approximately 3 minutes before it booted. The switch was last configured by user admin1 on May 27, 2009, and there is currently one user logged in to the switch.

The output also shows that the load average is 0.05 seconds for the last minute, 0.06 seconds for the last 5 minutes, and 0.01 seconds for the last 15 minutes.

Displaying the NTP Peers


Verify that the time has been obtained from an NTP server.


Enter the show ntp associations operational mode command to display the NTP server from switch obtained its time.

user@switch> show ntp associations


The asterisk (*) in front of the NTP server name, or peer, indicates that the time is synchronized and obtained from this server. The delay, offset, and jitter are displayed in milliseconds.

Displaying the NTP Status


View the configuration of the NTP server and the status of the system.


Enter the show ntp status operational mode command to view the status of the NTP.

user@switch> show ntp status


The output shows status information about the switch and the NTP.

