Set NTP server options?

King-of-Lag
Here to help

Set NTP server options?

I have 2 NTP servers - Stratum 1.

Why can't Merak use my time server(s) to sync off of?

10 Replies 10
Adam
Kind of a big deal

Some related discussions here

https://community.meraki.com/t5/Switching/NTP-server/td-p/9551

 

Adam R MS | CISSP, CISM, VCP, MCITP, CCNP, ITILv3, CMNO
If this was helpful click the Kudo button below
If my reply solved your issue, please mark it as a solution.
King-of-Lag
Here to help

Thanks Adam for the link, but not related.

 

  • I am not attempting to make the Meraki device into an NTP server or host NTP functions.
  • I want to make Meraki use my NTP servers.
BrandonS
Kind of a big deal

It's not an option, but I wonder why you want to?  It seems better to use what Meraki prefers because of the cloud management I could imagine the potential for issues if the appliance and cloud were using different servers.

- Ex community all-star (⌐⊙_⊙)
Adam
Kind of a big deal

Right but later in the thread they talk about how you can't set an NTP server for the Meraki but you can for downstream stuff via DHCP possibly.  

Adam R MS | CISSP, CISM, VCP, MCITP, CCNP, ITILv3, CMNO
If this was helpful click the Kudo button below
If my reply solved your issue, please mark it as a solution.
King-of-Lag
Here to help

Adam, NTP via DHCP is mostly not functional. Many companies simply fail to implement that part of the standard on their equipment. There are also a few viruses that utilize NTP injection through DHCP offers. Again its not to make the Meraki an NTP server. I want Meraki to use my NTP servers for accurate time sync.

MerakiDave
Meraki Employee
Meraki Employee

@King-of-Lag in most/all recent firmware versions, NTP actually happens over the mtunnel connections that all Meraki devices make back to their cloud controllers.  Only if there's no response for some reason, they would then leverage public NTP servers.  See your point though, and it's a good one, especially at large scale.  Still, when NTP is happening via mtunnel (let's say 99.999% of the time) it's all part of that very lightweight (roughly 1Kbps on average) control plane connection.  I'd still discuss it with your Meraki or Meraki Partner contacts and have them check if there's an FR in the system already, and if not perhaps create one.

 

sbcoms
Here to help

Hi, so does Meraki have an option/support for local time zone display via NTP UTC. Thus allowing admins to view events in their local time zone?

Bruce
Kind of a big deal

@sbcoms for every Meraki network (a Meraki network is essentially a container for all the devices at a site/location) you specify the Timezone, all the reporting for that Meraki network is then shown in that Timezone. The configured Timezone for a site is also used when setting schedules for SSIDs, etc., so that you don’t need try and do any conversions.

King-of-Lag
Here to help

Spankym, I would want to use my NTP service because its local. it has higher reliability and lower latency. Its also a stratum 1 and not a 2 or 3 like some of them on the NTP.org options or time.google.com. Mine also support PTP services for higher accuracy, so why not use them?

 

Also since I have thousands of devices already pulling NTP, I want to limit as much as possible any more use of my WAN connection than what is needed. When you get into larger networks, security and bandwidth conservation become a necessity for hosted or remote accessible service offerings so that bandwidth, buffer packet rates, and system resources remain optimal.

MerryAki
Building a reputation

How do i configure NTP using DHCP? comma separated?

MerryAki_0-1649776311317.png

multiple entries were not allowed.

MerryAki_2-1649776408421.png

 

RFC describes it at packetlayer:

MerryAki_1-1649776377851.png

RFC 2132: DHCP Options and BOOTP Vendor Extensions (rfc-editor.org)
Thanks 🙌

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels