I'm configuring a building wide network of layer2 and layer3 ciscos to use NTP but I'm not getting ntp updates from the ntp servers. Drawing a picture of this would have a Collapsed Core of 2 4500s and 2950 Access switches are 2950s setup based on Cisco's typical building block network diagram.
The only deviation from Cisco's typical designs is that the mangement vlan has been changed from the default VLAN on all switches (pretty typical, and obviously the same VLAN on all of the switches). However, we've removed it from the trunk interfaces. Instead, a separate network of 2950 switches is used as the management network that's connected to each of the switches. Everything on the management VLAN works: telnet, ssh, tftp, etc. No problems.
When I configure one or even both of the 4500 switches using ntp master, everything looks good on that switch. "show ntp status" shows the switch is configured with it's time deviations, etc. However, I cannot get any other switch to see this ntp server. They are setup with the ntp server <ip of core switch>. Even if options are used such as source or version, it still never sees the ntp master. I've also tried creating ntp peer <ip address> of all the switches on both the core and access switches. Nothing... The peer switches always show "Not connected"
I've gone two steps further and possibly more off track to troubleshoot the problem, but nothing works. The other things I've tried is to use a Mandriva system configured as an NTP server (master) that's on that management vlan and set the switches up to look to it as the server. I've also tried to configure the core switch to look at one of the non-management vlan computers for the master (which is crazy at best since the switches IP is on the management vlan, but it was worth testing for a sanity check).
Does anyone have any other ideas? I'd include print outs of the CLI, but it wouldn't help. Basically, show ntp status shows "Not connected" on the peer/downlevel switches and even the core doesn't show a connection when using the Mandriva system as the NTP master.
All switches are configured to forward UDP ntp and time as well as the management VLAN. I have an access-list on each of the management interfaces for all switches that restrict management only traffic in/out of that interface.
If anyone else has any experience with such as setup as this and knows a solution, please let me know.
October 24, 2005 10:25 PM
October 25, 2005 12:21 PM