NTP on Nexus5k and 3560

I have begun moving NTP from our 6500 to 4 Nexus 5k as part of a core upgrade.  The Nexus will act as our internal NTP server for all switches.  Any switches that are on the same vlan as the Nexus have no issues syncing NTP from them.  However any switch that has to have the traffice routed to the Nexus is showing that the time source as insane.
The configuration on our Nexus is as follows the Nexus are .11,12,13 and 14:
ntp peer 172.24.1.12
ntp peer 172.24.1.13
ntp peer 172.24.1.14
ntp server 192.43.244.18
clock timezone CST -6 0
clock summer-time CDT 2 Sun Mar 2:00 1 Sun Nov 2:00 60
Here is the configuration on one of our 3560's:
clock timezone CST -6
clock summer-time CDT recurring
ntp server 172.24.1.11
ntp server 172.24.1.13
ntp server 172.24.1.12
ntp server 172.24.1.14
This same configuration worked when the switches were configured as NTP Peers to our 6500 (172.24.1.1).  The ip for the 6500 has been moved to an HSRP address across the Nexus so I have pointed the switches at the individual IP for each Nexus.
Here is a debug ntp packet ouput from one of the 3560s:
.Mar  7 17:21:22: NTP: xmit packet to 172.24.1.11:
.Mar  7 17:21:22:  leap 3, mode 3, version 3, stratum 0, ppoll 64
.Mar  7 17:21:22:  rtdel 2445 (141.678), rtdsp C804D (12501.175), refid AC180101
(172.24.1.1)
.Mar  7 17:21:22:  ref D2F4A4F5.9CBFA919 (06:32:53.612 CST6 Sun Feb 26 2012)
.Mar  7 17:21:22:  org 00000000.00000000 (18:00:00.000 CST6 Thu Dec 31 1899)
.Mar  7 17:21:22:  rec 00000000.00000000 (18:00:00.000 CST6 Thu Dec 31 1899)
.Mar  7 17:21:22:  xmt D3021792.8D0B8963 (11:21:22.550 CST6 Wed Mar 7 2012)

Thanks for your reply.
My issue may be a little different than you encountered. In my configuration I am able to get some, but not all, SVIs on Nexus 5548s to funciton as NTP servers.
I have two Nexus 5548 vPC peers configured (N5K-1 and N5K-2) for HSRP and as NTP servers. A downstream 2960S switch stack (STK-7) is the NTP client. STK-7 is connected to N5K-1 and N5K-2 with a physical link each bundled into a port channel (multi-chassis Etherchannel on the STK-7 stack and vPC on the 5548 peers).
When the STK-7 NTP client is configure for NTP server IP addresses on the same network as the switch stack (10.3.0.0 in the diagram below) all possible IP addresses work (IP addresses in green), the “real” IP addresses of each SVI on the 5548s (10.3.0.111 & 10.3.0.112) as well as the HSRP IP address (10.3.0.1).
When the STK-7 NTP client is configured for NTP server IP addresses on a different network than the switch stack (10.10.0.0 in the diagram below) only the “real” IP address of the SVI on the 5548 to which the Etherchannel load-balancing mechanism directs the client to server NTP traffic (N5K-2) works. In the diagram above the client to server NTP traffic is sent on the link to N5K-2. In the diagram below NTP server 10.10.0.112 is reported as sane but NTP servers 10.10.0.111 and 10.10.0.1 are reported as insane (in red).
I am concerned that the issue is related to my vPC configuration.
Cisco TAC has indicated that this behavior is normal.

Similar Messages

  • Daisy chain of 3550 and 3560

    Can we use a mixture of 3550 and 3560 in a daisy chain. What i mean is
    1.if i want to connect 4 switches in a daisy chain can two of them be 3550's and the other two be 3560's.
    2. If i ahve 2 3550's in a daisy chian can i add one more 3560 to the same chain

    it may be more beneficial to aggregate 3 of the switches to one via the GB/SFP ports.
    ie:
    switch1-3560 >> switch2
    switch1-3560 >> switch3
    switch1-3560 >> switch4
    having correctly sized ports for aggregated bandwidth will be required.
    you can also perform daisy chaining as you've asked.

  • Need to synch NTP on 2100 and 4400 Wireless LAN Controllers

    I have 5 WLC's (3-2100, 2-4400) and need to synch the NTP server ip addresses on them.  I know how to do this but have a question.  Using the gui, once I apply the change to the NTP ip address and save the changes, will the WLCs need to be rebooted for them to complete synchronization?

    No, you don't have to reboot the controllers.  They should sync right up.

  • Two 2911 routers and 3560 switches (load balancing and redundancy)

    Good day, Sir !
    I have a model with hierarchical model. Two routers 2911 and two core switches 3560, two providers.
    I want to design redundancy scheme. Can you advice me how is better to do it ? here you can find image with topology, can you say is it good idea to connect with devices in this way ?
    Hope on you help ! Thank you !!!

    Hi,
    If you want to configure redundancy in your network on LAN you can use HSRP and from the WAN side depending on the connection with the provider you can either use BGP or any IGP.
    If you want to have load balancing as well with redundancy you can define differnt  HSRP group for different  vlan and on the wan with BGP you can use multipath option or with IGP you can manipulate the route matric.
    Thanks & Regards
    Sandeep

  • AAA and 3560 Switch + CNA

    Hi
    Has anyone got this to work?
    CNA. (Cisco Networks Assistants) and AAA (Tacacs+) on a 3560 switch.
    I can’t get the CNA to work in this setup but it works fine on together with 3500XL and 3550 serie switch. With the same parameter.
    this is the aaa conf.
    aaa authentication login default group tacacs+ local
    aaa authentication login no_tacacs enable
    aaa authentication enable default enable group tacacs+ none
    aaa authorization exec default group tacacs+ local
    aaa authorization exec no_tacacs none
    aaa authorization commands 15 default group tacacs+ if-authenticated local
    aaa authorization commands 15 no_tacacs none
    aaa accounting exec default start-stop group tacacs+
    aaa accounting commands 15 default start-stop group tacacs+
    aaa accounting network default start-stop group tacacs+
    ip http server
    ip http authentication aaa

    Hi
    No. I get the prompt for username and password.
    and hit enter. Then nothing happens. It looks like it's trying to build the network but it never get fines. I know it works without the aaa statement. But I can’t live with that.

  • NTP on Cat2900XL and Cat3500XL switches

    Can these switches be configured using NTP with "ntp server x.x.x.x"? The Configuration guide was saying that it can configure this but the command reference did not have this command, only "ntp broadcast client"! It's kinda confusing and I do not have a switch (of these series) on hand to confirm it.
    Please advise. Thank you.

    Hi,
    It is possible to configure NTP on XL switches. I am using a 3500XL switch and ntp is configured in it.
    Might differ with the IOS being used.
    3500XL#sh ver
    Cisco Internetwork Operating System Software
    IOS (tm) C3500XL Software (C3500XL-C3H2S-M), Version 12.0(5)XU, RELEASE SOFTWARE (fc1)
    Copyright (c) 1986-2000 by cisco Systems, Inc.
    Compiled Mon 03-Apr-00 17:31 by swati
    Image text-base: 0x00003000, data-base: 0x00301398
    ROM: Bootstrap program is C3500XL boot loader
    System image file is "flash:c3500XL-c3h2s-mz-120.5-XU.bin"
    cisco WS-C3548-XL (PowerPC403) processor (revision 0x01) with 16384K/1024K bytes of memory.
    Processor board ID 0x17, with hardware revision 0x00
    Last reset from power-on
    Processor is running Enterprise Edition Software
    Cluster command switch capable
    Cluster member switch capable
    48 FastEthernet/IEEE 802.3 interface(s)
    2 Gigabit Ethernet/IEEE 802.3 interface(s)
    32K bytes of flash-simulated non-volatile configuration memory.
    Configuration register is 0xF
    #### NTP Config ###
    ntp authentication-key 11111 md5 1234567
    ntp authenticate
    ntp trusted-key 11111
    ntp clock-period 11259058
    ntp server x.x.x.x key 11111
    ### NTP Association status ###
    3500XL#sh ntp assoc
    address ref clock st when poll reach delay offset disp
    *~x.x.x.x y.y.y.y 2 4 64 377 1.6 -0.43 1.3
    * master (synced), # master (unsynced), + selected, - candidate, ~ configured
    3500XL#
    thanks,
    Naveen V

  • Private vlans and 2960 and 3560 switch

    Hi, I have a 3560 switch that supports private vlans. There are few computers connected to it and private vlans work fine. Now I need to connect a 2960 switch to 3560 switch. 2960 seems to have no private vlan configuration options but it can be private vlan edge? What is private vlan edge? If I put the computers on 2960 to a vlan that is isolated vlan in 3560 will the computers be able to communicate with themselves in layer2 on 2960 switch?

    Example: I have network 10.0.0.0/24. Networks primary vlan is 2001, isolated is 2002 and community is 2003. These settings are on 3560. So if I put computers on 2960 switch to vlan 2002 and make the ports protected ports they will act as isolated ports and they can't communicate with ports that are on isolated vlan 2002 on 3560???
    Can I also use the community vlan on 2960? is this possible because vlans 2002 and 2003 would be on the same network???

  • NTP Issue on cisco 3560 switch

    Hi all 
    Here is my ntp configuration 
    clock timezone GMT 4
    clock summer-time UAE recurring
    ntp server 192.168.10.254 version 2 prefer
    end
    sh ntp status 
    Clock is unsynchronized, stratum 16, no reference clock
    nominal freq is 119.2092 Hz, actual freq is 119.2092 Hz, precision is 2**17
    reference time is 00000000.00000000 (04:00:00.000 GMT Mon Jan 1 1900)
    clock offset is 0.0000 msec, root delay is 0.00 msec
    root dispersion is 0.00 msec, peer dispersion is 0.00 msec
    -SW1#sh ntp associations
          address         ref clock     st  when  poll reach  delay  offset    disp
     ~192.168.10.254   0.0.0.0          16     -    64    0     0.0    0.00  16000.
     * master (synced), # master (unsynced), + selected, - candidate, ~ configured
    -SW1#
    Please help me what i have did wrong 
    regards
    raja

    You are still not answering the question.  
    Is the appliance, with IP Address 192.168.10.254, synchronized with a valid SNTP/NTP address or not. 
    Even if you enable NTP Master (which I personally don't recommend) and your appliance is NOT synchronized to a valid NTP source, then the appliance 192.168.10.254 can potentially broadcast the WRONG time to all the appliance.  Since you've forced all downstream appliances to synchronize with a source that has the wrong NTP data (using the command "ntp master") all your network equipment will be sporting the wrong time.

  • Cable interconnecting Cat. 3550 and 3560

    What would be an appropiate cable connecting the 3550 catalyst and the 3560?
    3550 has 2 gbic ports, while the 3560 has 4 spf module slots.

    . Can the Cisco Catalyst 3560 Series switches support the GigaStack® or StackWise™ technology?
    A. The Cisco Catalyst 3560 switches do not support the Cisco GigaStack Technology on the Catalyst 3550, 2950G, and 3500 XLs or the Cisco StackWise technology available on the Catalyst 3750. However, a cluster of any combination of these platforms can be managed via a single IP address using the Cisco Network Assistant (CAN) software. There are more details on CNA later in this document.

  • 3560 PoE and 3560

    hello
    i have an enhanced image running on 3560PoE switch for dynamic routing. can i copy this image to 3560 switch which is not a PoE switch.
    is there a different ios image for poe switches

    Hi
    No there is not a separate IOS image for PoE so memory and flash considerations aside you should have no problem with this.
    HTH
    Jon

  • Sfp interconnect between 2960 and 3560

    Hi,
    Can anyone tell me if the sfp interconnect cable can be used between 2960-48TC-L and a 3560-48PS-E?
    Thanks
    Andy

    in short, YES.
    the 3560-48PS-E has the 4 SFP ports.
    the 2960-48TC-L has two 'dual purpose' uplinks which can support SFP or copper.
    (you can only use one type at a time; not SFP and copper simultaneously)
    please see the following links for more info on those two devices:
    2960 -
    http://www.cisco.com/en/US/products/ps6406/products_data_sheet0900aecd80322c0c.html
    3560 -
    http://www.cisco.com/en/US/products/hw/switches/ps5528/products_data_sheet09186a00801f3d7d.html

  • VLAN's, subinterface, access-lists and 3560 catalyst switch?

    Hi,
    How can I isolate VLAN 121 from all others?
    I have a cisco 2811 router connected to a 3560 catalyst switch which has 5 VLAN's of which I need to protect IP traffic of 4 from 1.
    The following VLANs configured on the switch:
    VLAN 0 192.168.132.0 /24
    VLAN 135 ..135.0 /24
    VLAN 137 ..137.0 /24
    VLAN 139 ..139.0.24 and lastly,
    VLAN 121 192.168.121.0 /24 which I wish to isolate all IP from VLAN 0, 135, 137, and 139 but have internet out the 2811's other interface. Currently all VLAN's and routing are working perfectly.
    I need some advice please. Here is my plan:  to split the FA0/0 into FA0/0.1 for VLAN 121 using dot1q and apply an access-list to deny 192.168.121.0 to the FA0/0 interface. Since I'm essentially creating VLAN's with the router can or will that interfere with the Switch VLAN configuration? router on a stick vs. a Layer 4 Cisco 3560 Catalyst switch?
    Thank you!

    I will have to assume VLAN 0 is the native VLAN / default interface on the router?  All VLANs are numbered native or not.  Just ensure the VLAN numbering matches between the router and the trunking on the switch.
    Yes, you could create a sub interface on the 2811 and use the router to route the VLAN.  Apply an access list on the other interfaces to block access to the VLAN you want to protect.  If you have routing enabled on the 3560 as well you would complicate the situation a bit more. 
    Please rate helpful posts! :-)

  • Password showing in running configuration on 3750's and 3560's

    Hi All,
    Forigve the stupid question here but I was just backing up the running configuration on the switches at work before we have a big powerdown at the weekend and I noticed that the passwords to access the switches are showing in readable text in the running configuration. Under line vty 0.4 and line vt 5.15 there is an entry for the password.
    I have never seen this before in cisco switch running configurations so I was just wondering if it was normal? I'm new to the company so before I go rock the boat I thought I would ask if it is just a normal occurance as I've never seen it before on other 29 series switches that I have worked with.
    If it isn't normal should I just remove it from the configuration files and then write mem to write a new config file minus the passwords? Just seems a bit risky to have passwords showing in plain sight especially if somebody ever saw the configuration file?
    Any advice on the above would be greatly appreciated?
    Thanks.

    Thanks when I try entering the command service password-encryption I get invalid marker detected at the third character in the word service is their a condensed form of this command so that I can turn this service on please?
    I am trying to enable the service password-encryption from the elevated access mode on the switch or do I need to be in just the normal mode? I thought that in order to make any configuration changes and be able to write those changes to memory you had to be in the elevated access mode?

  • Configuration of GBIC on 2950 and 3560 switches

    Can someone please advise how to configure a "GBIC T Base Port" on a 2950 switch. I have 2 off and would like to load share and provide redundacy. All documentation that I am aware of does not indicae that they support etherchannel configuration.

    Step 1
    configure terminal
    Enter global configuration mode.
    Step 2
    interface interface-id
    Specify a physical interface to configure, and enter interface configuration mode.
    Valid interfaces include physical interfaces.
    Up to eight interfaces of the same type and speed can be configured for the same group.
    Step 3
    switchport mode {access | trunk}
    switchport access vlan vlan-id
    Assign all interfaces as static-access ports in the same VLAN, or configure them as trunks.
    If you configure the interface as a static-access port, assign it to only one VLAN. The range is 1 to 4094.
    Step 4
    channel-group channel-group-number mode
    {{auto [non-silent] | desirable [non-silent] | on} | {active | passive}}
    For more detail see Etherchannel configuration Guide:
    http://www.cisco.com/univercd/cc/td/doc/product/lan/cat2950/12122ea5/2950scg/swethchl.htm

  • LLDP between Nexus5K and HP VC module

    Hi all,
    Has anyone of you ever connected a N5K to a HP Virtual Connect module and run LLDP on this connection ?
    In my lab, they don't seem to be compatible as the N5K doesn't see anything ? I though LLDP was a vendor-independent standard ?
    # sh lldp neigh
    LLDP Neighbors
    PS. I am running NX-OS 4.1(3)N2(1a)
    regards,
    Geert

    Yesterday, I just upgraded from 2.33 to 3.16.
    I encountered problems :
         VCM must be in BAY 1
         VCM must me alone in BAY 1 or with a VCM module in BAY 2 (I tryed with GbE2c in BAY 2)
    I used vcsu 1.5.2 and all workded fine.
    Before these upgrades, all the blade and the enclosure (C3000) where in lastest version.
    BIOS : 2010-25-10 B
    iLo2 : 2.05
    OA : 3.21
    Then I plugged the VCM and made the upgrade.

Maybe you are looking for

  • How do I get my playlists back onto my iphone after itunes match?

    just signed up for itunes match and all my original playlists (the ones I used to sync with my itunes on my computer) are gone.  How do i get these back on my iphone?

  • Select query taking more time..

    Hi friends.. The below inner join statement is taking more time ,  can any  body sugget me to improve the performance . I tried FOR ALL ENTRIES also but that also taking more time than inner join statement . SELECT a~vbeln from vbap as a inner join v

  • Black Thumbnails in Finder

    Document thumbnails in Finder and in menus appear black. Also page thumbnails when in a particular document appear black. See below. How can I fix this? /Users/jamesjagoda/Desktop/screen-capture.png /Users/jamesjagoda/Desktop/screen-capture-1.png Tha

  • Java objects to Flex

    Hopefully this is the right forum, if not pleas accept my apologies. We need to return dollars and percent type numbers from java back to Flex using the BlazeDS interface. When I create a Java test object to return that looks like: public class Test2

  • Concurrent makes my data double!

    Dear friends, The question as follows: I have one table named my_tab which has tow columns ID(PK) and NAME. my_tab firstly has no datas.and remeber there are a constant that value is "Oracle" . I have write a pl/sql package one of its procedure will