Guided buildcore7 steps~20 min3 devices
Give the whole network one clock
Build an NTP hierarchy from HQ to a branch switch, read the strata hop by hop, then find the security ACL that silently broke time while ping kept working.
What you'll be able to do: Every device agrees on the time — HQ-Core at stratum 3, the branch router at 4, the branch switch at 5 — and the branch's WAN filter lets time in from HQ and from nowhere else.
Topics: NTP · ACLs · Network security
What you'll build
- HQ-Core — a router, the headquarters router and the network's time source
- Branch-Edge — a router, the branch router, a client of HQ and a server for its LAN
- SW-Branch — a switch, the branch access switch that takes its time locally
Step by step
1. Join HQ and the branch with a WAN link
Drag two routers on, name them HQ-Core and Branch-Edge, and join their Se0/0/0 ports with a serial cable. A /30 gives the link exactly two usable addresses: .1 for HQ, .2 for the branch.
- Cable HQ-Core Se0/0/0 ↔ Branch-Edge Se0/0/0 (serial)
On HQ-Core — Name the HQ router and address its end of the WAN link
enable configure terminal hostname HQ-Core interface Se0/0/0 ip address 10.0.12.1 255.255.255.252 no shutdown exit endOn Branch-Edge — Name the branch router and address its end of the WAN link
enable configure terminal hostname Branch-Edge interface Se0/0/0 ip address 10.0.12.2 255.255.255.252 no shutdown exit endCheck: run
show ip interface briefon Branch-Edge and look forSe0/0/0 10.0.12.2 YES manual up up.Why: NTP is an ordinary UDP service riding on IP. Before any clock can be shared, the two routers have to reach each other; time is the payload, the WAN link is just the road.
2. Point the branch at HQ — before HQ keeps time
Tell Branch-Edge where its time comes from with ntp server 10.0.12.1, then read show ntp associations. HQ is listed, but its reference is .INIT., its stratum 16 and its reach 0: HQ-Core does not run NTP yet, so nothing answers, and an unsynchronised clock is stratum 16 by definition.
On Branch-Edge — Name HQ-Core as the branch's time server
enable configure terminal ntp server 10.0.12.1 endCheck: run
show ntp associationson Branch-Edge and look for~10.0.12.1 .INIT. 16 - 64 0 0.000 0.000 15937..Why: A client only follows a server that is itself synchronised. A configured server that never answers leaves the clock free-running, which is why reach and stratum are the first two columns to read.
3. Make HQ-Core the time source
ntp master 3 tells HQ-Core to trust its own clock and serve it at stratum 3. The branch syncs at once, one stratum further down: show ntp status on Branch-Edge now reads synchronized, stratum 4, reference 10.0.12.1.
On HQ-Core — Serve HQ-Core's own clock at stratum 3
enable configure terminal ntp master 3 endCheck: run
show ntp statuson Branch-Edge and look forClock is synchronized, stratum 4, reference is 10.0.12.1.Why: Stratum is distance from the reference clock: each hop down the hierarchy adds one, and 16 means unsynchronised. In production the top of the tree syncs to an external stratum 1 or 2 source; the lab has no internet, so HQ-Core's own clock plays that part.
4. Bring the branch switch onto the network
Give Branch-Edge a LAN port on 192.168.60.0/24, cable the branch switch to it, and put a management address on the switch's VLAN 1 interface with the router as its default gateway. That SVI is the switch's own IP identity — the address it speaks NTP, SSH and syslog from.
- Cable Branch-Edge Gi0/0 ↔ SW-Branch Gi0/1
On Branch-Edge — Address the branch LAN port and bring it up
enable configure terminal interface Gi0/0 ip address 192.168.60.1 255.255.255.0 no shutdown exit endOn SW-Branch — Name the switch and give it a management address and gateway
enable configure terminal hostname SW-Branch interface vlan 1 ip address 192.168.60.2 255.255.255.0 no shutdown exit ip default-gateway 192.168.60.1 endCheck: run
show ip interface briefon SW-Branch and look forVlan1 192.168.60.2 YES manual up up.Why: Every device whose logs you will ever line up needs the same clock, switches included. A switch with no management address cannot take part in NTP at all.
5. Sync the switch to its local router
Point SW-Branch at Branch-Edge, not at HQ: ntp server 192.168.60.1. It syncs at stratum 5 — its router's stratum plus one. That is the hierarchy: HQ serves the branch routers, each branch router serves its own LAN, and no switch has to cross the WAN for time.
On SW-Branch — Take time from the branch router
enable configure terminal ntp server 192.168.60.1 endCheck: run
show ntp statuson SW-Branch and look forClock is synchronized, stratum 5, reference is 192.168.60.1.Why: Syncing locally keeps the load off HQ and the WAN: one query per branch crosses the link instead of one per device. The stratum number tells you exactly how far down the tree each clock sits.
6. A security change breaks time — and ping says all is well
The security team asks that nobody outside the branch can set its clocks, and the first attempt is one deny line, inbound on the WAN port. Apply it, then ping HQ-Core from Branch-Edge: the ping works. Now read show ntp status — the branch has fallen to stratum 16, and SW-Branch with it, because HQ's replies are NTP too and the filter drops them on the way in.
On Branch-Edge — Block inbound NTP on the WAN port, then test the path with ping
enable configure terminal ip access-list extended WAN-IN deny udp any any eq ntp permit ip any any exit interface Se0/0/0 ip access-group WAN-IN in end ping 10.0.12.1Check: run
show ntp statuson Branch-Edge and look forClock is unsynchronized, stratum 16, no reference clock.Why: An ACL matches protocols and ports, not intentions. A ping proves that ICMP gets through and nothing else, so a service can be dead on a path that answers every ping — test the service itself.
7. Let HQ through, keep everyone else out
This CLI cannot insert a line into an existing list, so delete WAN-IN and write it again in the right order: permit NTP from HQ-Core's address, then deny NTP from anyone else, then permit the rest. Deleting a list here also removes it from the port, so bind it again. The router reads top down and stops at the first match — HQ's replies now meet the permit first, and the branch climbs back to stratum 4, the switch to 5.
On Branch-Edge — Rewrite the WAN filter permit-first and bind it again
enable configure terminal no ip access-list extended WAN-IN ip access-list extended WAN-IN permit udp host 10.0.12.1 any eq ntp deny udp any any eq ntp permit ip any any exit interface Se0/0/0 ip access-group WAN-IN in endCheck: run
show access-listson Branch-Edge and look for10 permit udp host 10.0.12.1 any eq ntp.Why: Most filtering bugs are ordering bugs. With the narrow permit (one trusted server) above the broad deny (everyone else), the list finally says what the security team meant: time from HQ, and from nowhere else.
The theory behind it
More in Network services
- Let the router hand out the addresses — Build a four-device office LAN, address one PC by hand, then put a DHCP pool on the router so the next machine configures itself.
- One DHCP server for every floor — Serve a user floor from a central DHCP server on another subnet — watch the first request die at the router, then relay it with ip helper-address.
- Let the core switch hand out the addresses — Run two department VLANs, their gateways and their DHCP pools on a single switch — and find out why a perfect pool can still hand out nothing.
- NAT to the internet — Hide two private office LANs behind the single public address your provider gave you.
- Lock management down to SSH — Make a switch manageable from the admin subnet, then harden it: RSA keys, SSH version 2, a local account, and VTY lines that refuse everything but SSH.
Build it for real
The lab walks you through these steps and ticks each one off as your network starts working.
Open in the lab