cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1942
Views
0
Helpful
10
Replies

Cisco N5k NTP cannot sync

kevinang74
Level 1
Level 1

Anyone face this error before?

 

I have a pair of N5K connecting to 1 pair of FW. FW acts as my ntp server.

N5K also connect to a few N2K

Our config is:

ntp server x.x.x.x use-vrf management

ntp source-interface mgmt 0

 

Strange thing is SAN switch connected to N2K can sync with FW but N5K cannot.

I'm getting stratum 2 but it is not syncing.

 

10 Replies 10

Mark Malone
VIP Alumni
VIP Alumni
Hi
whats does the show ntp peer-status give ?
what nx-os version are you on , as the config is right thats all you need and reach ability to it , i presume thats right


show ntp peer-status
Total peers : 3
* - selected for sync, + - peer mode(active),
- - peer mode(passive), = - polled in client mode
remote local st poll reach delay vrf
-------------------------------------------------------------------------------
=172.21.17.xxx 0.0.0.0 3 64 377 0.00063 management
*172.21.7.xxx 0.0.0.0 3 64 377 0.00066 management
=172.21.7.xxx 0.0.0.0 3 64 377 0.00060 management

May also be worth checking the FW logs or captures to see the requests coming in from the nexus

Yes, can see request from nexus

Hi

My nx-os is 7.3.4(n1)1


My show ntp peer-status
Total peers : 1
* - selected for sync, + - peer mode(active),
- - peer mode(passive), = - polled in client mode
remote local st poll reach delay vrf
-------------------------------------------------------------------------------
=x.x.x.x y.y.y.y 2 16 377 0.00063 management

Quick search of that release 7.x shows good few NTP bugs , none specific to your release or issue though but it could be still software issues or as Shaps said the firewall may not be responding to it , is there another device you could point to as a test to rule the FW out ?

https://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus5500/sw/release/notes/7x/Nexus5500_Release_Notes_7x.html

The lack of NTP requests on the FW will certainly point to an NTP bug on the Nexus

I'm also suspecting it's a bug but i have catalyst 9300 running 16.10 that connects directly to the same firewall which is also not syncing.

What is syncing are SAN storage and SAN switches which are connected to N2K which are connected to N5K.

Jaderson Pessoa
VIP Alumni
VIP Alumni

Hi there,

 

Could you sets your correctly TIMEZONE

 

Example:

switch(config)# clock timezone EST -5 0

 

and check if your has synchronized?

 

Regards

 

Jaderson Pessoa
*** Rate All Helpful Responses ***

Yes, time zone set correctly

Besides timezone, any other things I should check?