All guided builds

Guided buildcore7 steps~20 min3 devices

Give the whole network one clock

Build an NTP hierarchy from HQ to a branch switch, read the strata hop by hop, then find the security ACL that silently broke time while ping kept working.

What you'll be able to do: Every device agrees on the time — HQ-Core at stratum 3, the branch router at 4, the branch switch at 5 — and the branch's WAN filter lets time in from HQ and from nowhere else.

Topics: NTP · ACLs · Network security

What you'll build

Step by step

  1. 1. Join HQ and the branch with a WAN link

    Drag two routers on, name them HQ-Core and Branch-Edge, and join their Se0/0/0 ports with a serial cable. A /30 gives the link exactly two usable addresses: .1 for HQ, .2 for the branch.

    • Cable HQ-Core Se0/0/0 ↔ Branch-Edge Se0/0/0 (serial)

    On HQ-Core — Name the HQ router and address its end of the WAN link

    enable
    configure terminal
    hostname HQ-Core
    interface Se0/0/0
    ip address 10.0.12.1 255.255.255.252
    no shutdown
    exit
    end

    On Branch-Edge — Name the branch router and address its end of the WAN link

    enable
    configure terminal
    hostname Branch-Edge
    interface Se0/0/0
    ip address 10.0.12.2 255.255.255.252
    no shutdown
    exit
    end

    Check: run show ip interface brief on Branch-Edge and look for Se0/0/0 10.0.12.2 YES manual up up.

    Why: NTP is an ordinary UDP service riding on IP. Before any clock can be shared, the two routers have to reach each other; time is the payload, the WAN link is just the road.

  2. 2. Point the branch at HQ — before HQ keeps time

    Tell Branch-Edge where its time comes from with ntp server 10.0.12.1, then read show ntp associations. HQ is listed, but its reference is .INIT., its stratum 16 and its reach 0: HQ-Core does not run NTP yet, so nothing answers, and an unsynchronised clock is stratum 16 by definition.

    On Branch-Edge — Name HQ-Core as the branch's time server

    enable
    configure terminal
    ntp server 10.0.12.1
    end

    Check: run show ntp associations on Branch-Edge and look for ~10.0.12.1 .INIT. 16 - 64 0 0.000 0.000 15937..

    Why: A client only follows a server that is itself synchronised. A configured server that never answers leaves the clock free-running, which is why reach and stratum are the first two columns to read.

  3. 3. Make HQ-Core the time source

    ntp master 3 tells HQ-Core to trust its own clock and serve it at stratum 3. The branch syncs at once, one stratum further down: show ntp status on Branch-Edge now reads synchronized, stratum 4, reference 10.0.12.1.

    On HQ-Core — Serve HQ-Core's own clock at stratum 3

    enable
    configure terminal
    ntp master 3
    end

    Check: run show ntp status on Branch-Edge and look for Clock is synchronized, stratum 4, reference is 10.0.12.1.

    Why: Stratum is distance from the reference clock: each hop down the hierarchy adds one, and 16 means unsynchronised. In production the top of the tree syncs to an external stratum 1 or 2 source; the lab has no internet, so HQ-Core's own clock plays that part.

  4. 4. Bring the branch switch onto the network

    Give Branch-Edge a LAN port on 192.168.60.0/24, cable the branch switch to it, and put a management address on the switch's VLAN 1 interface with the router as its default gateway. That SVI is the switch's own IP identity — the address it speaks NTP, SSH and syslog from.

    • Cable Branch-Edge Gi0/0 ↔ SW-Branch Gi0/1

    On Branch-Edge — Address the branch LAN port and bring it up

    enable
    configure terminal
    interface Gi0/0
    ip address 192.168.60.1 255.255.255.0
    no shutdown
    exit
    end

    On SW-Branch — Name the switch and give it a management address and gateway

    enable
    configure terminal
    hostname SW-Branch
    interface vlan 1
    ip address 192.168.60.2 255.255.255.0
    no shutdown
    exit
    ip default-gateway 192.168.60.1
    end

    Check: run show ip interface brief on SW-Branch and look for Vlan1 192.168.60.2 YES manual up up.

    Why: Every device whose logs you will ever line up needs the same clock, switches included. A switch with no management address cannot take part in NTP at all.

  5. 5. Sync the switch to its local router

    Point SW-Branch at Branch-Edge, not at HQ: ntp server 192.168.60.1. It syncs at stratum 5 — its router's stratum plus one. That is the hierarchy: HQ serves the branch routers, each branch router serves its own LAN, and no switch has to cross the WAN for time.

    On SW-Branch — Take time from the branch router

    enable
    configure terminal
    ntp server 192.168.60.1
    end

    Check: run show ntp status on SW-Branch and look for Clock is synchronized, stratum 5, reference is 192.168.60.1.

    Why: Syncing locally keeps the load off HQ and the WAN: one query per branch crosses the link instead of one per device. The stratum number tells you exactly how far down the tree each clock sits.

  6. 6. A security change breaks time — and ping says all is well

    The security team asks that nobody outside the branch can set its clocks, and the first attempt is one deny line, inbound on the WAN port. Apply it, then ping HQ-Core from Branch-Edge: the ping works. Now read show ntp status — the branch has fallen to stratum 16, and SW-Branch with it, because HQ's replies are NTP too and the filter drops them on the way in.

    On Branch-Edge — Block inbound NTP on the WAN port, then test the path with ping

    enable
    configure terminal
    ip access-list extended WAN-IN
    deny udp any any eq ntp
    permit ip any any
    exit
    interface Se0/0/0
    ip access-group WAN-IN in
    end
    ping 10.0.12.1

    Check: run show ntp status on Branch-Edge and look for Clock is unsynchronized, stratum 16, no reference clock.

    Why: An ACL matches protocols and ports, not intentions. A ping proves that ICMP gets through and nothing else, so a service can be dead on a path that answers every ping — test the service itself.

  7. 7. Let HQ through, keep everyone else out

    This CLI cannot insert a line into an existing list, so delete WAN-IN and write it again in the right order: permit NTP from HQ-Core's address, then deny NTP from anyone else, then permit the rest. Deleting a list here also removes it from the port, so bind it again. The router reads top down and stops at the first match — HQ's replies now meet the permit first, and the branch climbs back to stratum 4, the switch to 5.

    On Branch-Edge — Rewrite the WAN filter permit-first and bind it again

    enable
    configure terminal
    no ip access-list extended WAN-IN
    ip access-list extended WAN-IN
    permit udp host 10.0.12.1 any eq ntp
    deny udp any any eq ntp
    permit ip any any
    exit
    interface Se0/0/0
    ip access-group WAN-IN in
    end

    Check: run show access-lists on Branch-Edge and look for 10 permit udp host 10.0.12.1 any eq ntp.

    Why: Most filtering bugs are ordering bugs. With the narrow permit (one trusted server) above the broad deny (everyone else), the list finally says what the security team meant: time from HQ, and from nowhere else.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
Give the whole network one clock — step-by-step network lab · NetForge-AI