AdvancedPublished 2026-07-04
Building a Multi-Level NTP Hierarchy
Bundle lab
Lab 8 of 10 in NTP & Network Time · ← Previous · Next →
CCNA exam domain: IP Services
Create a deterministic three-tier NTP hierarchy on a single shared LAN. R1 is the authoritative clock (ntp master 2), R2 syncs to R1, and R3 syncs to R2. No routing or additional subnets — all devices share 10.0.0.0/24 via one L2 switch. Verify with show ntp status and show ntp associations.
Learning objectives
- Design and configure a three-tier NTP hierarchy on a flat LAN.
- Make a router an authoritative clock with ntp master <stratum> and explain stratum behavior.
- Chain NTP clients so each device syncs to the tier immediately above it.
- Verify NTP associations and expected stratum values deterministically without waiting for convergence.
- Differentiate ntp server (client/server) from implicit serving behavior once a device is synchronized.
- Apply disciplined verification using show ntp status and show ntp associations.
Troubleshooting focus
- If a tier does not show the expected stratum, confirm it points to the correct upstream IP and that upstream is configured with ntp master <stratum> (R1) or ntp server <ip> (R2).
- Check interface status and addressing on Ethernet0/0 across R1, R2, R3 — all must be up/up in 10.0.0.0/24.
- Avoid ntp peer in this hierarchy — use ntp server to form a strict parent-child chain.
- Verify no ntp access-group restrictions are unintentionally blocking associations (not used in this lab).
- Remember that live synchronization takes time — grade by configuration, not the star in show ntp associations.
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the
running-config— a change that only exists in a terminal session never reaches the grader. - You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.