Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

NTP (VRF) problem

Having a problem with NTP on an 1841 with VRFs. I have configured the following:

interface VlanX

description NTP interface

ip vrf forwarding NTP

ip address <ip address>

ntp authentication-key 1 md5 blahblah

ntp authenticate

ntp source VlanX

ntp master 2

ntp max-associations 2

ntp server vrf NTP <public address 1>

ntp server vrf NTP <public address 2>

ip route vrf NTP <public address 1>

ip route vrf NTP <public address 2>

ip route vrf NTP <internal address 1>

ip route vrf NTP <internal address 2>

There is only one gateway via VlanX (the firewall).

NTP requests to the two ntp servers go out (confirmed in debug), but I get no hits on the firewall, permit or deny or otherwise. If I execute a ping from my router in the NTP vrf I get the appropriate hit.

However, if I configure another ntp server command pointing to an internal host:

ntp server vrf NTP <internal address 1>

I get the appropriate hit on the firewall. Ideas on how I can troubleshoot this? I've checked the bug tracker and there is no software bug listed for this model/image/ntp -

c1841-advipservicesk9-mz.123-11.YZ2

2 REPLIES
VIP Super Bronze

Re: NTP (VRF) problem

Do you have s static route for the vrf

ip route vrf NTP x.x.x.x 255.255.255.255 x.x.x.x (vlan x)

New Member

NTP (VRF) problem

As I posted above:

"ip route vrf NTP

ip route vrf NTP

ip route vrf NTP

ip route vrf NTP "

Routes are fine - as I said I can ping the addresses and generate the correct entries on the firewall.

870
Views
0
Helpful
2
Replies